Vietnam's product-security and cyber-resilience posture now rests on a single consolidated statute, the Law on Cybersecurity, Law No. 116/2025/QH15, passed by the National Assembly on 10 December 2025 and in effect since 1 July 2026, which expressly repeals both of the two statutes it replaces, the 2015 Law on Cyberinformation Security (No. 86/2015/QH13) and the 2018 Law on Cybersecurity (No. 24/2018/QH14), on its own effective date.
Article 8 classifies every information system into five statutory levels by the damage an incident or a cybersecurity-law violation could cause, and Article 10 grades the manager's protection duty to that level: a level 1 or level 2 manager must perform every Article 10(1) task (determine the system's level, assess and manage its risk, supervise and inspect its protection activities, apply protection measures, follow the reporting regime, and raise awareness) and may choose which Article 10(2) measures to apply; a level 3 or level 4 manager whose system is not on the Prime Minister's list of information systems critical to national security must additionally, and mandatorily, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents, plus file a level-classification dossier and obtain approval before putting the system into operation.
Decree No. 331/2026/ND-CP, issued 19 August 2026 to detail Article 8(2), sets the actual classification criteria and procedure a manager applies to find its level.
A system the Prime Minister has placed on the list of information systems critical to national security under Article 9, a government designation rather than a declared activity, carries the full Article 10(1) and 10(2) obligation set plus its own appraisal, certification, and annual self-inspection regime under Article 11, and is recorded here as background rather than raised against a declared activity, the treatment this profile gives Japan's designated critical-infrastructure operator and Singapore's provider-owned critical information infrastructure.
Article 40(1)(c) separately requires any information system manager, at any level, to report a cybersecurity incident to the specialised cybersecurity protection force of the Ministry of Public Security or the Ministry of National Defence, and Article 41 layers a parallel duty on any domestic or foreign enterprise providing services on a telecommunications network, the Internet, or another value-added service in cyberspace in Vietnam: warn users of cybersecurity risks and give preventive guidance, keep an emergency response plan for cybersecurity weaknesses, risks and incidents, implement that plan and report an incident to the specialised force the moment it occurs, and apply technical measures to secure data processing, including personal-data processing.
Decree No. 330/2026/ND-CP, the administrative-sanctions decree issued the same day as Decree No. 331, prices both duty sets in Vietnamese dong, doubling the stated figure for an organisation.
The Law's own Article 25 imposes a further set of duties on the same enterprise class, real-name authentication of a user's digital account, a 24-hour clock (3 hours in an emergency) to hand a user's information to the specialised force, a 24-hour clock (6 hours in an emergency) to remove content that clock names, and in-country storage of personal information and service-usage data with a foreign branch or representative office requirement; these are content-moderation and data-localisation duties rather than a security-posture requirement and sit outside this topic, the same seam this corpus draws in every jurisdiction.
Vietnam's comprehensive data-protection statute, the Law on Personal Data Protection (Law No. 91/2025/QH15), carries this jurisdiction's breach-notification duty as its own privacy-topic row, and the Penal Code's unauthorised-access offence, an intruder's liability rather than an operator's, is this jurisdiction's scraping-topic row; neither is restated here.