Circular No. 29/2023/TT-NHNN on the management and use of electronic signatures, electronic certificates, and electronic signature verification services by the State Bank of Vietnam. This Circular takes effect from March 1, 2026, and replaces previous Circulars such as No. 28/2015/TT-NHNN and No. 16/2023/TT-NHNN.
适用范围
Heads of units under the State Bank of Vietnam, the National Treasury of Vietnam, the Deposit Insurance Corporation of Vietnam, credit organizations, foreign bank branches, service providers of payment intermediation, credit information companies.
要点
- Provisions on the issuance and management of electronic certificates for subscribers
- Responsibilities of the parties involved in the process of using electronic signatures
- Effective date from March 1, 2026
- Replacing previous circulars on the management and use of digital signatures and digital certificates.
- Transitional provisions for cases where digital certificates have been issued before the effectiveness of this Circular.
🌐 本文件的社会影响
- Enhancing security in electronic transactions
- Continuing administrative reform in the financial banking sector
❓ 常见问题
Which circulars does Circular No. 29/2023/TT-NHNN replace?
This Circular replaces Circular No. 28/2015/TT-NHNN and Circular No. 16/2023/TT-NHNN.
Which organizations must comply with this Circular?
Heads of units under the State Bank of Vietnam, the National Treasury of Vietnam, the Deposit Insurance Corporation of Vietnam, credit organizations, foreign bank branches, service providers of payment intermediation, credit information companies.
When does this Circular take effect?
Circular No. 29/2023/TT-NHNN takes effect from March 1, 2026.
全文
|
STATE BANK OF VIETNAM |
SOCIALIST REPUBLIC OF VIET NAM |
|
Number: 59/2025/TT-NHNN |
Hanoi, December 29, 2025 |
CIRCULAR
Regulations on the provision and use of specialized electronic signatures and specialized electronic signature certificates of the State Bank
Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12;
Pursuant to the Law on Information Technology No. 67/2006/QH11;
Pursuant to the Law on Electronic Transactions No. 20/2023/QH15;
Pursuant to the Law on Credit Organizations No. 32/2024/QH15 amended and supplemented by Law No. 96/2025/QH15;
Pursuant to the Government Decree No. 23/2025/NĐ-CP on electronic signatures and trusted services;
Pursuant to Decree No. 26/2025/NĐ-CP of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Department of Information Technology; information;
The Governor of the State Bank of Vietnam issues this Circular regulating the provision and use of specialized electronic signatures and specialized electronic signature certificates of the State Bank. This Circular regulates the provision and use of specialized electronic signatures and specialized electronic signature certificates of the State Bank of Vietnam (hereinafter referred to as the State Bank).
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
1. Units under the State Bank; credit organizations; foreign bank branches; service providers of payment intermediation; credit information companies; the National Treasury of Vietnam; Deposit Insurance Corporation of Vietnam.
Article 2. Applicability
2. Other organizations using specialized electronic signatures and specialized electronic signature certificates of the State Bank (hereinafter referred to as electronic signatures and electronic signature certificates) in electronic transactions organized by the State Bank.
1. The original electronic signature certificate is the certificate issued by the State Bank for itself during the process of establishing the State Bank's electronic signature certification system.
Article 3. Explanation of Terms
In this Circular, the following terms are understood as follows:
2. The State Bank's electronic signature certification system is an information system providing infrastructure and services for issuing, managing, verifying electronic signature certificates and ensuring the creation and verification of electronic signatures.
3. An electronic signature certificate is a certificate issued by the State Bank to subscribers to confirm that the subscriber has been certified as the person signing the electronic signature.
4. A subscriber is an organization or individual who is issued an electronic signature certificate by the State Bank.
5. Subscriber management organizations are units under the State Bank, credit organizations, foreign bank branches, service providers of payment intermediation, credit information companies, the National Treasury of Vietnam, Deposit Insurance Corporation of Vietnam, or other organizations managing subscribers using the State Bank's electronic signatures.
6. Secret key is a key in an asymmetric cryptographic key pair used to create electronic signatures.
7. Public key is a key in an asymmetric cryptographic key pair used to verify electronic signatures created by the corresponding secret key in the key pair.
8. Signer is a subscriber who uses their own secret key to electronically sign a data message under their name.
9. Recipient is an organization or individual receiving a data message electronically signed by the signer, using the signer's electronic signature certificate to verify the electronic signature in the received data message.
10. Activation code is information provided to subscribers including reference number and authentication code used to authenticate during the activation of electronic signature certificates.
11. Activating an electronic signature certificate is the process where a subscriber uses the activation code to authenticate, generate a key pair including the secret key and public key, and store it in a dedicated storage device (hereinafter referred to as key storage device).
12. Authorized person is the head of units under the State Bank or the legal representative or authorized representative of agencies and organizations specified in Article 2 of this Circular.
13. Electronic signature certificate transaction is a transaction on information systems where subscribers can use electronic signature certificates to approve or verify. An electronic signature certificate may be used to approve or verify on one or more information systems. Information systems using the State Bank's electronic signature certificates include:
a) The National Inter-bank Electronic Payment System;
b) The State Bank Reporting System;
c) The bidding and open market operations system including sub-systems of:
- Bidding and open market operations;
- Issuance, payment, extension, and cancellation of special bonds;
- Issuance of State Bank bills;
- Capital replenishment.
d) The information system supporting management, supervision, and prevention of fraud risks in payment activities;
đ) The anti-money laundering reporting system;
e) The information system serving the supervision of the operation of people's credit funds and microfinance organizations;
g) Other systems decided by the Governor of the State Bank.
g) Other systems decided by the Governor of the State Bank.
Article 4. Organizations creating electronic signatures, electronic signature certificates
The Information Technology Department is the lead unit managing, operating technical infrastructure, and creating electronic signatures, electronic signature certificates for the State Bank of Vietnam.
Article 5. Contents of electronic signature certificate
The electronic signature certificate issued by the State Bank of Vietnam includes the following contents:
1. Name of the State Bank of Vietnam.
2. Name of the subscriber.
3. Subscriber identification.
4. Certificate number of the electronic signature certificate.
5. Validity period of the electronic signature certificate.
6. Data for verifying the electronic signature of the agency, organization, or individual holding the electronic signature certificate.
7. Electronic signature of the State Bank of Vietnam.
8. Purpose and scope of use of the electronic signature certificate.
9. Legal responsibility of the State Bank of Vietnam.
Article 6. Sending and receiving applications for issuance of electronic signature certificates
1. Methods of sending and receiving applications
The subscriber management organization sends applications to the State Bank of Vietnam (Information Technology Department) through one of the following methods:
a) Electronic application submitted online at the National Public Service Portal;
b) Paper application submitted directly at the One-Stop Service Desk of the State Bank of Vietnam or sent via postal service;
c) Application sent through the Bank of Vietnam's Document Management and Operation System (applicable to units under the State Bank of Vietnam).
The Information Technology Department will only accept and process paper applications or applications sent through the Bank of Vietnam's Document Management and Operation System in cases where the National Public Service Portal cannot operate due to technical issues.
In cases where the organization has already submitted an electronic application through the National Public Service Portal or sent an application through the Bank of Vietnam's Document Management and Operation System, there is no need to send a paper application to the Information Technology Department.
2. Regulations on applications
a) For electronic applications
The subscriber management organization must fill out the corresponding electronic forms on the National Public Service Portal according to Appendices I to VII issued together with this Circular. For other documents in the application such as appointment decisions, authorization letters, or task assignments, the subscriber management organization must attach digital copies (PDF format) scanned from original documents.
b) For paper applications
The subscriber management organization has the right to choose to submit either the original or a copy (and present the original for verification upon request by the Information Technology Department).
3. Processing results of applications
The Information Technology Department will send an electronic document containing the processing result or the reason for rejection in case the application is not approved, to the subscriber management organization in accordance with regulations on administrative procedures under the one-stop mechanism. In cases where the administrative procedure information system encounters technical issues, the result will be sent to the subscriber management organization via postal service.
Article 7. Key storage devices for subscribers
1. The Information Technology Department is responsible for publishing on the State Bank of Vietnam’s electronic portal guidelines regarding types and technical specifications of key storage devices for subscribers.
2. The Information Technology Department provides key storage devices to administrative units under the State Bank of Vietnam. Non-administrative units under the State Bank of Vietnam and other subscriber management organizations must equip themselves with key storage devices in accordance with the guidelines of the Information Technology Department.
3. The sending and receiving of key storage devices between the Information Technology Department and administrative units under the State Bank of Vietnam shall be carried out through direct delivery or via postal service.
Chapter II
MANAGEMENT AND ISSUANCE OF ELECTRONIC SIGNATURE CERTIFICATES
Article 8. Management and issuance activities of electronic signature certificates
1. Issuance and supplementation of electronic signature certificate services.
2. Modification of information content in electronic signature certificates.
3. Change of activation code for electronic signature certificates.
4. Extension of electronic signature certificates.
5. Suspension of electronic signature certificates.
6. Restoration of electronic signature certificates.
7. Revocation and cancellation of electronic signature certificate services.
8. Maintenance of online database on electronic signature certificates.
Article 9. Issuance and supplementation of electronic signature certificate services
1. Issuance and supplementation of electronic signature certificate services for individuals
The application dossier for issuing or supplementing electronic signature certificate services for individuals includes:
a) Application form for issuing or supplementing electronic signature certificate services for individuals as stipulated in Appendix I attached to this Circular;
b) Document expressing the subscriber's consent for the Information Technology Department to collect and process personal data for issuing electronic signature certificates for subscribers as stipulated in Appendix VIII attached to this Circular;
c) In cases where the individual receiving the electronic signature certificate is an authorized person of a state agency or organization, the managing organization must submit along with the application dossier the decision appointing the authorized person;
d) In cases where the individual receiving the electronic signature certificate is an authorized person or assigned task by an authorized person, the managing organization must submit along with the application dossier the authorization or assignment document. The content of the authorization or assignment must clearly state that the authorized or assigned person is permitted to represent the organization in signing off on files, documents, reports, transactions on the corresponding information system according to the service of the requested electronic signature certificate. The authorized person may not delegate this authority to another person.
2. Issuance and supplementation of electronic signature certificate services for organizations
The application dossier for issuing or supplementing electronic signature certificate services for organizations includes: Application form for issuing or supplementing electronic signature certificate services for organizations as stipulated in Appendix II attached to this Circular.
3. In cases where the electronic signature certificate has been issued and expired or revoked, if the subscriber wishes to continue using it, they shall submit the application dossier as prescribed in Clause 1 of this Article for individual electronic certificates or Clause 2 of this Article for organizational electronic certificates to obtain a new replacement electronic signature certificate.
4. In cases where the electronic signature certificate has been issued and is still valid, but the key storage device is damaged or the electronic signature certificate is deleted from the device or due to other reasons leading to errors during use, if the subscriber wishes to continue using it, they shall submit the application dossier requesting the issuance of a replacement electronic signature certificate as follows:
a) For electronic signature certificates issued to individuals: Application form for issuing or supplementing electronic signature certificate services for individuals as stipulated in Appendix I attached to this Circular.
b) For electronic signature certificates issued to organizations: Application form for issuing or supplementing electronic signature certificate services for organizations as stipulated in Appendix II attached to this Circular.
The reissued electronic signature certificate will have an effective period equal to the remaining validity period of the most recent previously issued electronic signature certificate.
5. Time limit for processing and results of implementation
Within three working days from the date of receipt of a complete application dossier for issuing or supplementing electronic signature certificate services, the Information Technology Department will issue the electronic signature certificate or supplement the electronic signature certificate service for the subscriber. In the case of issuing an electronic signature certificate, the Information Technology Department will send the activation code along with the notification of issuance of the electronic signature certificate to the subscriber. In the case of supplementing the electronic signature certificate service, the subscriber does not need to reactivate the electronic signature certificate.
Within two working days from the date of receipt of the application dossier, in cases where the application dossier is incomplete, the Information Technology Department will refuse to process the dossier and specify the reason. Feedback information and results of dossier processing will be carried out in accordance with Clause 3 of Article 6 of this Circular.
6. The activation code for electronic signature certificates has a maximum validity period of thirty days from the date of issuance of the electronic signature certificate. Subscribers activate the electronic signature certificate according to the activation and extension guide for electronic signature certificates published on the State Bank of Vietnam’s website.
7. The maximum validity period of electronic signature certificates for subscribers is five years. In cases where the proposed validity period exceeds the remaining validity period of the original electronic signature certificate of the State Bank, the validity period of the issued electronic signature certificate for the subscriber will be the remaining validity period of the original electronic signature certificate of the State Bank.
Article 10. Extension and Change of Content of Electronic Signature Certificate Information
1. Conditions for Extension and Change of Content of Electronic Signature Certificate Information
a) The electronic signature certificate must ensure its validity;
b) The organization managing the subscriber must submit an application for extension or change of content of the electronic signature certificate information at least 10 days before the expiration date of the electronic signature certificate.
2. Validity Period of the Electronic Signature Certificate
a) The validity period of the electronic signature certificate is calculated from the successful extension date. In cases where the proposed validity period exceeds the remaining validity period of the original electronic signature certificate issued by the State Bank, the validity period of the extended electronic signature certificate will be the remaining validity period of the original electronic signature certificate issued by the State Bank;
b) Changing the content of the electronic signature certificate information does not alter the validity period of the electronic signature certificate.
3. Cases for Changing the Content of Electronic Signature Certificate Information
a) The subscriber changes their position or title;
b) The subscriber changes their address, email, phone number, or passport information;
c) The subscriber changes their department (room/division) but does not change the unit/branch. In cases where the subscriber changes to a different unit/branch, the managing organization must carry out procedures to revoke the electronic signature certificate at the old unit/branch and issue a new electronic signature certificate at the new unit/branch if the subscriber requests to continue using it;
d) In cases where there is a policy for restructuring state organizations or administrative units leading to a need to change the information of the electronic signature certificate, the Information Technology Department sends a notification to the managing organization and implements the change of information of the electronic signature certificate of the subscriber.
4. The managing organization submits one set of application documents for extension or change of content of the electronic signature certificate information as specified in point a, b, and c of Clause 3 of this Article, including the Application for Extension and Change of Content of the Electronic Signature Certificate Information according to Appendix III attached to this Circular.
5. Time limit for processing and results of implementation
Within two working days from the date of receiving valid applications for extension or change of content of the electronic signature certificate, the Information Technology Department will process the extension or change of content of the electronic signature certificate for the subscriber.
Within one working day from the date of receipt of the application, in cases where the application is not valid, the Information Technology Department will reject the processing of the application and clearly state the reasons. Feedback information and results of the application processing will be carried out according to the provisions of Clause 3 of Article 6 of this Circular.
Upon receiving notification of approval for the extension of the electronic signature certificate, the subscriber shall extend the electronic signature certificate according to the activation and extension guide for the electronic signature certificate published on the State Bank's electronic portal.
Article 11. Suspension of the Electronic Signature Certificate
1. Cases for Suspension of the Electronic Signature Certificate of the Subscriber
a) The managing organization has submitted an application for suspension of the electronic signature certificate of the subscriber;
b) At the request in writing of the prosecution agency, the police agency, or the Ministry of Science and Technology in accordance with the provisions of the law;
c) The Information Technology Department discovers errors or incidents that may affect the rights of the subscriber or the security of the State Bank's electronic signature certification system.
2. The suspension period of the electronic signature certificate under point a of Clause 1 of this Article is based on the proposal of the managing organization. The suspension period of the electronic signature certificate under point b of Clause 1 of this Article is based on the request of the prosecution agency, the police agency, or the Ministry of Science and Technology. The suspension period of the electronic signature certificate under point c of Clause 1 of this Article lasts until the errors or incidents have been resolved.
3. The managing organization submits one set of application documents for suspending the electronic signature certificate, including the Application for Suspension of the Electronic Signature Certificate according to Appendix IV attached to this Circular.
4. Time Limit for Processing and Results
a) Within one working day from the date of receiving a valid application for suspension of the electronic signature certificate as stipulated in point a of Clause 1 of this Article, the Information Technology Department will suspend the electronic signature certificate of the subscriber and notify the managing organization of the result of the processing;
Within one working day from the date of receipt of the application, in cases where the application is not valid, the Information Technology Department will reject the processing of the application and clearly state the reasons. Feedback information and results of the application processing will be carried out according to the provisions of Clause 3 of Article 6 of this Circular;
b) Within one working day from the date of receiving the request document as stipulated in point b of Clause 1 of this Article, the Information Technology Department will suspend the electronic signature certificate and notify the managing organization in writing of the suspension time and reason;
c) For the provision in point c of Clause 1 of this Article, the Information Technology Department will suspend the electronic signature certificate after discovering errors or incidents and notify the managing organization of the reason for the suspension of the electronic signature certificate.
Article 12. Restoration of Electronic Signature Certificates
1. The electronic signature certificate to be restored must ensure that it is currently within the suspension period.
2. Circumstances for restoring electronic signature certificates of subscribers
a) The subscriber management organization has submitted a restoration application for the electronic signature certificate that was suspended according to point a, Clause 1, Article 11 of this Circular;
b) Judicial authorities, public security agencies, or the Ministry of Science and Technology have issued a document requesting the restoration of the electronic signature certificate that was suspended according to point b, Clause 1, Article 11 of this Circular;
c) The electronic signature certificate was suspended according to point c, Clause 1, Article 11 of this Circular, and the errors or incidents causing the suspension have been resolved;
d) The suspension period for the electronic signature certificate according to the suspension request has expired.
3. The subscriber management organization shall submit one set of documents for the restoration application of the electronic signature certificate according to point a, Clause 2 of this Article, including the Application for Restoration of Electronic Signature Certificate attached as Appendix V to this Circular.
4. Time Limit for Processing and Results
a) Within one working day from the date of receiving a valid restoration application for the electronic signature certificate according to point a, Clause 2 of this Article or a document requesting restoration according to point b, Clause 2 of this Article, the Information Technology Department shall restore the electronic signature certificate for the subscriber.
Within one working day from the date of receiving the documents, if the documents are not valid, the Information Technology Department will refuse to process them and provide the reasons. Feedback information and processing results shall be carried out according to Clause 3, Article 6 of this Circular;
b) For the provisions at points c and d, Clause 2 of this Article, the Information Technology Department will automatically restore the electronic signature certificate and notify the subscriber management organization.
Article 13. Revocation and Cancellation of Electronic Signature Certificate Services
1. The subscriber management organization may request the revocation or cancellation of one or more services of the electronic signature certificate of the subscriber. In the case of revoking the electronic signature certificate, all services of the electronic signature certificate of the subscriber will be canceled.
2. Circumstances for revoking the electronic signature certificate of the subscriber
a) At the written request of judicial authorities, public security agencies, or the Ministry of Science and Technology in accordance with the law;
b) The subscriber management organization has submitted a revocation application for the electronic signature certificate of the subscriber;
c) The subscriber management organization has a decision to revoke the operating license, split, merge, dissolve, or declare bankruptcy according to the law;
d) There is sufficient evidence to determine that the subscriber has violated regulations on managing and using electronic signature certificates and storage devices;
đ) The electronic signature certificate has expired.
3. The subscriber management organization shall submit one set of documents for the revocation or cancellation of electronic signature certificate services, including the Application for Revocation or Cancellation of Electronic Signature Certificate Services attached as Appendix VI to this Circular.
4. Time Limit for Processing and Results
a) Within one working day from the date of receiving the document requesting revocation or cancellation of electronic signature certificate services according to point a, Clause 2 of this Article or a valid revocation or cancellation application for electronic signature certificate services from the subscriber management organization according to point b, Clause 2 of this Article, the Information Technology Department shall carry out the revocation or cancellation of electronic signature certificate services for the subscriber.
Within one working day from the date of receiving the documents, if the documents are not valid, the Information Technology Department will refuse to process them and provide the reasons. Feedback information and processing results shall be carried out according to Clause 3, Article 6 of this Circular;
b) For the provisions at points c, d, and đ, Clause 2 of this Article, the Information Technology Department will automatically revoke the electronic signature certificate of the subscriber and send a notification to the subscriber management organization.
Article 14. Changing the Activation Code for Digital Signature Certificates
1. Situations for changing the activation code for digital signature certificates
a) The activation code has been disclosed or suspected to have been disclosed;
b) The activation code has expired, the subscriber has not activated the digital signature certificate, and there is a need to continue using the digital signature certificate.
2. The management organization shall submit one set of application documents for changing the activation code, including the Application for Changing the Activation Code for Digital Signature Certificate as stipulated in Appendix VII issued together with this Circular.
3. Time limit for processing and results
Within two working days from the date of receipt of a valid application for changing the activation code for digital signature certificates, the Department of Information Technology shall change the activation code for the digital signature certificate for the subscriber and notify the subscriber of the new activation code for the digital signature certificate.
Within one working day from the date of receipt of the application, in cases where the application is not valid, the Information Technology Department will reject the processing of the application and clearly state the reasons. Feedback information and results of the application processing will be carried out according to the provisions of Clause 3 of Article 6 of this Circular.
4. The activation code for the digital signature certificate shall be valid for a maximum period of thirty days from the date of change. The subscriber shall activate the digital signature certificate according to the activation and renewal guidelines published on the State Bank of Vietnam's electronic portal.
Article 15. Updating and Announcing Information
The Department of Information Technology shall publish, update, and maintain twenty-four hours a day, seven days a week, on the State Bank of Vietnam's electronic portal the following information:
1. The original digital signature certificate of the State Bank of Vietnam.
2. The regulation on certification of the State Bank of Vietnam.
3. A list of digital signature certificates that are valid, temporarily suspended, or revoked for subscribers.
4. Guidelines and software related to the management and use of digital signatures and digital signature certificates of the State Bank of Vietnam.
5. Other necessary information as prescribed by law.
Chapter III
RESPONSIBILITIES OF THE PARTIES INVOLVED IN PROVIDING AND USING DIGITAL SIGNATURES AND DIGITAL SIGNATURE CERTIFICATES
Article 16. Responsibilities of the Department of Information Technology
1. Issuing, renewing, suspending, revoking, restoring, supplementing business operations, canceling business operations, changing activation codes, and changing information on digital signature certificates when requested.
2. Managing and operating technical infrastructure and having plans to ensure continuous, secure, and confidential operation of the State Bank of Vietnam’s digital signature certification system.
3. Researching and advising the Governor of the State Bank of Vietnam on technical solutions and technological infrastructure to meet the needs for development and expansion of the State Bank of Vietnam’s digital signature certification system.
4. Ensuring security and confidentiality throughout the process of issuing and transferring activation information for digital signature certificates to subscribers. Updating and securely storing subscriber information for managing digital signature certificates. Adhering to laws regarding personal data protection in collecting, processing, and storing subscriber information.
5. Distributing digital signature certificates and key storage devices to subscribers in accordance with regulations.
6. Providing subscribers with information about the scope and authority of use of digital signature certificates, security requirements, and other information that may affect the rights of subscribers.
7. Storing information related to the temporary suspension or revocation of digital signature certificates for at least five years from the date of suspension or revocation.
8. Publishing a list of active, temporarily suspended, or revoked digital signature certificates.
9. Providing and updating software and materials related to activating, renewing digital signature certificates, managing key storage devices, signing and verifying digital signatures of the State Bank of Vietnam.
Article 17. Responsibilities of the organization managing subscribers
1\. Designate an individual or department responsible for registering, managing subscriber lists, managing files, documents, and reports related to the management and use of electronic signatures and electronic signature certificates issued by the State Bank.
2\. Register and bear full responsibility for the accuracy of information in documents, files, and reports related to electronic signature certificates of subscribers under management submitted to the Information Technology Department.
3\. Manage, statistically analyze, and update the subscriber list within the organization. At least once every three months, conduct a review and comparison between the list of electronic signature certificates issued by the State Bank and the actual needs and information of the subscriber management organization. For electronic signature certificates that do not match the information, the subscriber management organization must carry out procedures to change information, temporarily suspend, revoke, or cancel the electronic signature certificate business.
4\. Notify subscribers under management about providing personal data and authorize the Information Technology Department to collect and process personal data to issue electronic signature certificates for subscribers. Provide the Information Technology Department with a document expressing the subscriber's consent for the Information Technology Department to collect and process personal data to issue electronic signature certificates for subscribers as stipulated in Article 9 of this Circular.
5\. Guide, inspect, and facilitate subscribers under management to register and use electronic signature certificates in accordance with the provisions of this Circular.
6\. Timely notify the Information Technology Department to suspend or revoke the electronic signature certificate of subscribers in the following cases:
a\. The subscriber's secret key is suspected of being disclosed, leaked, stolen, or used improperly;
b\. The subscriber's key storage device is lost;
c\. The subscriber changes their job position without needing to use an electronic signature certificate for work purposes;
d\. The subscriber is on temporary leave, has retired, or passed away;
e\. The subscriber belongs to a branch/unit of the subscriber management organization whose bank code has been revoked;
f\. When the authorization document from the legal representative for the person receiving the electronic signature certificate expires or another authorization document replaces it;
g\. Other cases arising from the needs of the subscriber management organization.
7\. Key storage devices and electronic signature certificates provided to the organization must be handed over to individuals for management and use. The handover must be documented clearly defining the roles and responsibilities of the individual assigned to manage. The individual assigned to manage must fulfill the roles and responsibilities of the subscriber as stipulated in this Circular.
8\. Inspect and supervise the management and use of key storage devices and electronic signature certificates by subscribers to ensure safety and proper purpose. Reclaim key storage devices from subscribers when they leave their job, transfer positions, or change job positions where the job does not require the use of an electronic signature certificate. Upon reclaiming, the key storage device must ensure that all stored data has been deleted by the subscriber.
9\. The subscriber management organization, which is an administrative unit under the State Bank, must promptly reclaim key storage devices from subscribers under management who no longer need them for reuse by other subscribers within the unit.
Article 18. Obligations of the Subscriber
1. Provide complete and accurate personal information and data (for individual subscribers) to serve the issuance of electronic signature certificates by the State Bank.
2. Use the electronic signature certificate within the scope and purpose for which it was issued. Adhere to the provisions on the responsibilities of the signer when using the issued electronic signature certificate as stipulated in Clause 1, Article 19 of this Circular.
3. Management and use of key storage devices
a) Use the correct type of key storage device according to the guidance of the Information Technology Department;
b) Ensure the security and confidentiality of access codes and data stored in the issued key storage device;
c) Do not share access codes or lend key storage devices. Upon resignation, job transfer, or change in position where the work no longer requires the use of the electronic signature certificate, destroy the stored data in the key storage device and hand over the device to the subscriber management organization;
d) Do not use any tools, programs, software, or other means to interfere with, modify, or change the information of the electronic signature certificate, data in the key storage device, or intentionally damage the device;
đ) Promptly notify the subscriber management organization if the electronic signature certificate is no longer secure, or if the key storage device is lost, malfunctioning, or damaged and cannot be used.
4. Comply with other regulations regarding the issuance, management, and use of electronic signature certificates.
Article 19. Obligations of the Signer and Recipient
1. Obligations of the Signer
Do not sign electronic signatures on data messages on information systems when the system indicates that the status of the electronic signature certificate is no longer valid.
2. Obligations of the Recipient
The recipient shall only accept electronic signatures from the signer on data messages of information systems when the system confirms that the signer's signature is valid after checking the following information:
a) Verify the validity, usage scope, and liability limits of the signer's electronic signature certificate;
b) The electronic signature must be created by the private key corresponding to the public key guaranteed by the issued electronic signature certificate.
3. The signer and recipient are responsible for any damages that may occur due to non-compliance with the provisions of Clauses 1 and 2 of this Article.
Chapter IV
IMPLEMENTING PROVISIONS
Article 20. Effective Date
1. This Circular takes effect from March 1, 2026.
2. Circular No. 28/2015/TT-NHNN of the Governor of the State Bank on the management and use of digital signatures, digital certificates, and digital signature certification services of the State Bank, and Circular No. 16/2023/TT-NHNN of the Governor of the State Bank amending and supplementing certain provisions of Circular No. 28/2015/TT-NHNN shall cease to be effective from the date this Circular takes effect, except as provided in Article 21 of this Circular.
Article 21. Transitional Provisions
1. Digital certificates issued to subscribers before the effective date of this Circular and remain valid on the effective date of this Circular may continue to be used until their expiration date or until they are reissued in accordance with this Circular.
2. Applications for State Bank digital signature certification services submitted by subscriber management organizations to the Information Technology Department but not completed by the effective date of this Circular shall continue to be processed under Circular No. 28/2015/TT-NHNN and Circular No. 16/2023/TT-NHNN.
Article 22. Implementation organization
The heads of units under the State Bank of Vietnam, the National Treasury of Vietnam, the Deposit Insurance Corporation of Vietnam, credit institutions, foreign bank branches, organizations providing payment intermediary services, and credit information companies shall be responsible for organizing the implementation of this Circular./.
| DIRECTOR DEPUTY GOVERNOR (Signed) Pham Tien Dung |
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。