Cybersecurity Law, Information System Classification and Protection Measures
Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 77 days, effective 1 July 2026.
A security baseline statutes rule binding public and private bodies.
As of 16 September 2026.
What it requires
- This duty binds now: Law No. 116/2025/QH15 took effect 1 July 2026, and Decree No. 331/2026/ND-CP, which sets the classification criteria, has applied since 19 August 2026.
- Determine which of the five statutory levels your information system falls into, based on the damage an incident or a cybersecurity-law violation could cause to lawful rights and interests, public interests, social order and safety, or national security.
- At level 1 or level 2, perform every Article 10(1) task (determine your system's level, assess and manage its cybersecurity risk, supervise and inspect its protection activities, apply protection measures, follow the reporting regime, and raise cybersecurity awareness), and choose which Article 10(2) measures to apply based on your own needs and capacity.
- At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.
- This duty does not describe a system the Prime Minister has placed on the list of information systems critical to national security: that class carries the full Article 10(1) and 10(2) obligation set plus its own appraisal, certification and annual self-inspection regime under Articles 9 and 11, gated on a government designation rather than a declared activity.
If you get it wrong
Private right of actionNo
Penalty structure
Decree No. 330/2026/ND-CP, art. 23 states two individual fine tiers, doubled for an organisation under art. 7(1): failing to promulgate cybersecurity design-and-operation rules, or, for a level 3 to level 5 system, failing to file a classification dossier, putting the system into operation without an approved level, or incompletely deploying the measures the approved level requires, draws VND 20,000,000 to 30,000,000 for an individual (VND 40,000,000 to 60,000,000 for an organisation); failing to inspect, supervise, log, or assess the effectiveness of the applied measures draws VND 30,000,000 to 50,000,000 for an individual (VND 60,000,000 to 100,000,000 for an organisation), the figure this row's fixed_cap states.
- Rule
- Fixed only
- As of
- 16 September 2026
- Currency
- VND
- Fixed cap
- 100,000,000
Who enforces it
Enforcement body
The specialised cybersecurity protection force of the Ministry of Public Security, which the Law makes the focal agency for state administration of cybersecurity; the Ministry of National Defence for a military information system.
Settledness
- As of
- 16 September 2026
- Open questions
- Does Article 10's classification duty reach a foreign enterprise's information system that serves users in Vietnam but keeps no branch, representative office, or physical infrastructure there?
What it reaches
Obligation class
Governance, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 8 sorts every information system into one of five levels by the damage a cybersecurity incident or violation could cause, and Article 10 grades a manager's protection duty to that level, reaching any manager, state or private, of a level 1 to level 4 system; a system on the Prime Minister's list of information systems critical to national security carries a fuller, separately gated regime under Articles 9 and 11.
Decree No. 331/2026/ND-CP, effective 19 August 2026, sets the classification criteria and the approval procedure the Law's Article 8(2) delegates to the Government.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product