Law / Vietnam

Cybersecurity Law, Information System Classification and Protection Measures

Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 77 days, effective 1 July 2026.

A security baseline statutes rule binding public and private bodies.

As of 16 September 2026.

What it requires

  • This duty binds now: Law No. 116/2025/QH15 took effect 1 July 2026, and Decree No. 331/2026/ND-CP, which sets the classification criteria, has applied since 19 August 2026.
  • Determine which of the five statutory levels your information system falls into, based on the damage an incident or a cybersecurity-law violation could cause to lawful rights and interests, public interests, social order and safety, or national security.
  • At level 1 or level 2, perform every Article 10(1) task (determine your system's level, assess and manage its cybersecurity risk, supervise and inspect its protection activities, apply protection measures, follow the reporting regime, and raise cybersecurity awareness), and choose which Article 10(2) measures to apply based on your own needs and capacity.
  • At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.
  • This duty does not describe a system the Prime Minister has placed on the list of information systems critical to national security: that class carries the full Article 10(1) and 10(2) obligation set plus its own appraisal, certification and annual self-inspection regime under Articles 9 and 11, gated on a government designation rather than a declared activity.

If you get it wrong

Private right of actionNo

Penalty structure

Decree No. 330/2026/ND-CP, art. 23 states two individual fine tiers, doubled for an organisation under art. 7(1): failing to promulgate cybersecurity design-and-operation rules, or, for a level 3 to level 5 system, failing to file a classification dossier, putting the system into operation without an approved level, or incompletely deploying the measures the approved level requires, draws VND 20,000,000 to 30,000,000 for an individual (VND 40,000,000 to 60,000,000 for an organisation); failing to inspect, supervise, log, or assess the effectiveness of the applied measures draws VND 30,000,000 to 50,000,000 for an individual (VND 60,000,000 to 100,000,000 for an organisation), the figure this row's fixed_cap states.

Rule
Fixed only
As of
16 September 2026
Currency
VND
Fixed cap
100,000,000

Who enforces it

Enforcement body

The specialised cybersecurity protection force of the Ministry of Public Security, which the Law makes the focal agency for state administration of cybersecurity; the Ministry of National Defence for a military information system.

Settledness

As of
16 September 2026
Open questions
Does Article 10's classification duty reach a foreign enterprise's information system that serves users in Vietnam but keeps no branch, representative office, or physical infrastructure there?

What it reaches

Obligation class

Governance, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 8 sorts every information system into one of five levels by the damage a cybersecurity incident or violation could cause, and Article 10 grades a manager's protection duty to that level, reaching any manager, state or private, of a level 1 to level 4 system; a system on the Prime Minister's list of information systems critical to national security carries a fuller, separately gated regime under Articles 9 and 11.

Decree No. 331/2026/ND-CP, effective 19 August 2026, sets the classification criteria and the approval procedure the Law's Article 8(2) delegates to the Government.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

English translation, LuatVietnam, Law No. 116/2025/QH15

Back to the example  ·  Lint your app