Tuesday, August 11, 2026, 10:03 (GMT+7)

Monday, August 10, 2026, 15:19 (GMT+7)
New points of the 2025 Law on Cybersecurity

Vietnam’s Law on Cybersecurity 116/2025/QH15 was passed by the 15th National Assembly at its 10th session on 10 December 2025 and came into force on 1 July 2026. The Law institutionalises the Party’s lines and the State's policies on protecting national security, placing cybersecurity protection activities under the Party’s leadership and the State’s unified management.

Cybersecurity Law 116/2025/QH15 (hereinafter referred to as the 2025 Law on Cybersecurity) was developed on the basis of inheriting and consolidating the provisions of the 2015 Law on Network Information Security and the 2018 Law on Cybersecurity. The Law comprises 8 chapters and 45 articles, providing for cybersecurity, cybersecurity protection, and the rights, obligations, and responsibilities of relevant agencies, organisations, and individuals.

A conference held by the Ministry of National Defence and the Ministry of Public Security on the 2025 Draft Law on Cybersecurity (photo: qdnd.vn)

The Law applies to Vietnamese agencies, organisations, and individuals, foreign agencies, organisations, and individuals in Vietnam, as well as persons of Vietnamese origin residing in Vietnam whose nationality has not been determined yet but who have been issued with identity certificates, and foreign agencies, organisations, and individuals directly participating in or involved in cybersecurity protection activities or in the provision of cybersecurity products and services in Vietnam. The Law introduces several principal new points as follows. 

1. The Law refines and standardises the fundamental concepts of cybersecurity in order to remove the previous inconsistencies between the concepts of “network information security” and “cybersecurity” in the legal system, thereby establishing a clear, coherent legal basis for the process of implementation.

The Law standardises the interpretation and scope of the concept of “cybersecurity”. Clause 1, Article 2 stipulates: “Cybersecurity means the stability, security, and safety of cyberspace, the protection of information systems, and the guarantee that information, data, and activities in cyberspace shall not be detrimental to national security, social order and safety, or the legitimate rights and interests of agencies, organisations, and individuals”

The Law clearly identifies the concept of “network information security” as the technical pillar of cybersecurity. Clause 2, Article 2 provides: “Network information security means ensuring the integrity, confidentiality, and availability of information in cyberspace, preventing unauthorised access, use, disclosure, modification, or destruction, or any other acts that threaten or undermine national security and social order and safety”. The substance of this concept distinguishes technical and technological protection requirements from the broader political, legal, social requirements of cybersecurity protection, thereby facilitating the development and adoption of technical measures to protect information infrastructure.

The Law supplements the concept of “data security” to meet the requirements set by the digital era. Clause 3, Article 2 specifies: “Data security means ensuring the quality of data and the processing and use of data in cyberspace in support of socio-economic development and national digital transformation, avoiding unauthorised access, use, disclosure, modification or destruction, or any other acts that threaten or undermine national security and social order and safety”. This is a new point reflecting a shift in management thinking, recognising data as a strategic resource that must be protected and utilised.

The Law affirms digital sovereignty via the concept of “national cyberspace”. Clause 6, Article 2 provides: “National cyberspace means the portion of cyberspace that falls under the sovereignty, jurisdiction, and control of the Socialist Republic of Vietnam”. This provision is of significant importance in the context of intensive international integration and the growing volume of cross-border activities in cyberspace.

2. The Law refers to many new acts of violation arising from the application of advanced technologies, thus forming a comprehensive legal basis for the prevention, detection, and handling of violations in cyberspace.

Point (g), Clause 2, Article 7 introduces a prohibition on the unlawful use of artificial intelligence or new technologies to create fake videos, images or voices of other persons. This provision establishes a direct legal basis for handling fraudulent activities conducted through fake video calls, as well as acts of defamation and slander using image- and video-manipulation technologies.

With regard to financial, monetary, and digital market sectors, Point (d), Clause 1, Article 7 prohibits the dissemination of fabricated or false information relating to finance, banking, e-commerce, multi-level marketing, stock and bond markets, and similar fields that may cause public panic and damage the economy. In addition, Point (e), Clause 4, Article 13 stipulates that establishing or providing unauthorised services for digital asset exchanges, virtual currency trading platforms, or organising illegal multi-level marketing activities in cyberspace constitutes an act of violating national security. To strengthen the protection of digital identities and personal data, Point (h), Clause 2, Article 7 prohibits the unlawful collection, use, dissemination, exchange, or commercial trading of personal information and personal data.

Furthermore, Point (g), Clause 4, Article 13 identifies the use of false identities or forged documents to register bank accounts, digital accounts, or create “ghost accounts” for criminal purposes as an act of violating social order and safety. This provision aims to prevent online fraud and money laundering in cyberspace.

3. The Law improves the tier-based cybersecurity protection mechanism for information systems by adopting a management approach according to levels of risk and the importance of each information system, replacing the previous model of fragmented protection.

Clause 1, Article 8 classifies information systems into 5 levels. Such classification, from Level 1, where incidents affect only the managing organisation or individual, to Level 5, where incidents may cause exceptionally serious harm to national security, serves as the legal basis for defining the corresponding protection requirements and responsibilities. Article 10 prescribes cybersecurity protection responsibilities proportionate to the level of risk. More specifically, for Level 1 and Level 2 information systems, system owners may proactively select and adopt protection measures appropriate to their needs, conditions, and actual capabilities. For Level 3 and Level 4 information systems (excluding systems classified as critical to national security), a number of basic security measures are mandatory, including issuing internal regulations, applying technical standards and regulations, deploying firewalls, maintaining data backups, and carrying out monitoring and incident response. These provisions both ensure cybersecurity requirements and help optimise compliance costs for enterprises, particularly small and medium-sized ones.

For information systems playing a particularly important role, such as those in the military, security, finance - banking, energy, and transport sectors, the Law prescribes the highest level of protection as follows. (i) They must undergo cybersecurity appraisal and obtain certification confirming that they satisfy the requirements of cybersecurity before being put into operation. (ii) They must conduct continuous cybersecurity monitoring, perform annual cybersecurity self-inspections, and submit written inspection results to the specialised cybersecurity force before October each year. (iii) They must establish self-warning mechanisms and incident response and recovery projects, while closely coordinating with the Ministry of Public Security (MPS) and the Ministry of National Defence (MND) in monitoring and handling cybersecurity-related incidents. The above tier-based cybersecurity protection mechanism enables the State and society to effectively mobilise and utilise resources in order to safeguard critical infrastructure, ensure the security, stability, and continuous operation of information systems of importance to national security against increasingly complex threats and challenges in cyberspace.

4. The Law places emphasis on the responsibilities of enterprises providing telecoms, Internet, and value-added services in cyberspace in Vietnam by shifting from a voluntary coordination mechanism to mandatory legal obligations applicable uniformly to both domestic and foreign enterprises operating in Vietnam.

Point (b), Clause 2, Article 25 stipulates that enterprises are responsible for blocking the sharing of illegal information, removing such information, and taking down services or applications containing illegal content no later than 24 hours after receiving a request from the specialised cybersecurity protection force under the MPS. In urgent cases involving a risk to national security or social order and safety, the duration for response is reduced to no more than 6 hours.

The Law requires enterprises to proactively take both technical and managerial preventive measures. Under Clause 1, Article 14, information system owners and service providers must adopt necessary managerial and technical measures to prevent, detect, block, and promptly remove information containing illegal content, including propaganda against the State, incitement to riots, disruption of national security and social order, and infringement of the legitimate rights and interests of agencies, organisations, and individuals.

To eliminate sources of unlawful information at their origin, the Law clearly specifies that enterprises must refuse to provide services, or must terminate the provision of services to organisations or individuals that post seriously illegal content upon the request of the specialised cybersecurity protection force under the MPS. Point (c), Clause 2, Article 25 authorises the adoption of this measure to acts of violating national security and social order and safety, thereby strengthening both its deterrent effect and its preventive effectiveness.

The above provisions contribute to improving the role and social responsibility of enterprises in the digital environment, affirming that enterprises are not merely profit-making entities but also an important component of the national cybersecurity protection system, working towards the establishment of a cyberspace that is safe, healthy, and sustainable for users.

5. The Law formulates an independent status of the concept of “data security” within the legal system. This reflects a fundamental shift in the State's approach to cybersecurity governance, from an approach focused primarily on technical infrastructure protection to one centred on data protection - the core digital resource underpinning the digital economy and digital society.

The Law establishes “data security” as an independent, comprehensive legal concept. Whereas previous legislation mentioned data protection only in a fragmented manner under the broader concept of information security, the 2025 Law on Cybersecurity provides a specific definition of “data security” in Clause 3, Article 2. Accordingly, data security extends beyond preventing unauthorised access to, destruction of, or theft of data. It also includes ensuring the integrity, accuracy, availability, and utilisation of data in support of socio-economic development and national digital transformation.

The Law creates a comprehensive legal framework for ensuring data security. Article 26 prescribes measures for safeguarding data security, including applying technical standards and regulations, using cryptographic measures to protect data, controlling personnel involved in data processing, and conducting periodic data security risk assessments. Notably, for the first time, the Law requires the inspection and assessment of cross-border data transfer, thus enhancing the State's capacity to manage data flows, particularly important and core data, in order to prevent data leakage or misuse that could harm national interests.

In addition, Point (h), Clause 2, Article 7 expressly provides that the illegal collection, use, dissemination, exchange, transfer, or commercial trading of personal information and personal data represent a prohibited act.

6. The Law supplements provisions on the protection of children in cyberspace, while extending protection requirements to older persons and individuals with impaired cognitive capacity or limited ability to control their behaviour.

Clause 2, Article 16 clearly stipulates that parents or legal guardians are responsible for managing and supervising children's access to and use of information and services in cyberspace. Where children use services requiring account registration, the account must be registered in the name of a parent or legal guardian, who shall be responsible for the use of that account.

Pursuant to Clause 3, Article 16 and Clause 2, Article 25, enterprises providing online services are required to adopt necessary technical and managerial measures to detect, prevent, and promptly remove content involving child abuse, incitement to violence, pornography, obscenity, or inducement of children to engage in unlawful acts. At the same time, enterprises must establish convenient mechanisms and tools enabling users to quickly report inappropriate content relating to children.

Older persons and individuals with cognitive impairments or limited behavioural capacity are particularly vulnerable to online fraud and cyber-enabled property appropriation. Hence, Clause 5, Article 16 introduces a new provision requiring competent State agencies and enterprises providing online services to formulate appropriate support mechanisms and early-warning systems and give priority to receiving and handling reports, complaints, and denunciations concerning online fraud affecting these vulnerable groups.

7. The Law encourages research, development, and application of science and technology in the field of cybersecurity, prioritising investment in domestic cybersecurity infrastructure, products, and services, requiring appropriate resources to be allocated for cybersecurity protection in digital transformation and information technology projects, from design and budgeting to implementation stages.

Article 37 specifies that investment and business relating to cybersecurity products and services, as well as technical infrastructure construction for cybersecurity protection, fall within the list of business sectors and professions eligible for special investment incentives. The State shall apply preferential policies on taxation, land, and administrative procedures in order to encourage both domestic and foreign organisations and enterprises to invest in cybersecurity technology research and development. 

Clause 4, Article 3 expressly stipulates that State agencies and organisations shall give priority to using domestic cybersecurity products and services, provided that they satisfy technical, quality, and security requirements.

Clause 1, Article 38 requires agencies using State budget to allocate at least 15% of the total funding for digital transformation and information technology projects, to cybersecurity protection. With regard to funding, Clause 2, Article 38 specifies that financial resources allocated for cybersecurity protection shall be used to invest in technical equipment, procure advanced security solutions, acquire cybersecurity monitoring and incident response services, and provide training and professional development for specialised personnel. These provisions lay a sustainable financial foundation for the digital transformation process. The clear and consistent allocation of financial resources for cybersecurity demonstrates the State’s strong commitment to integrating cybersecurity with sustainable development. Adequately protected information systems will operate safely and reliably in the face of increasingly complex cybersecurity threats and challenges, thereby improving the effectiveness of public investment, reducing risks and losses, and ensuring the continuity of socio-economic activities in the digital environment.

8. The Law forms a legal basis for expanding and fostering international cooperation in cybersecurity on the basis of respect for national independence, sovereignty, and interests, incorporating the fundamentals of the United Nations Convention against Cybercrime (the Hanoi Convention) into domestic law.

The Law sets a relatively comprehensive legal framework, enabling Vietnam to participate more deeply and substantively in international cybersecurity cooperation mechanisms, firmly safeguarding national interests. Accordingly, the 2025 Law on Cybersecurity affirms the Party's absolute leadership over and the State's unified management of cybersecurity, identifying cybersecurity protection as a crucial and routine task of the entire political system and people, with the specialised force playing a core role. The provisions of the Law demonstrate a shift in thinking from defence to proactiveness and self-reliance in safeguarding cybersecurity, with emphasis on actively preventing, detecting, combating, and neutralising threats whenever necessary. At the same time, the Law gives priority to investing in science and technology development, enhancing national self-reliance in cybersecurity, harmoniously combining cybersecurity protection with socio-economic development, guaranteeing human rights and citizens' rights, creating favourable conditions for national digital transformation, digital economy, and digital society, forming a legal framework for effectively preventing, combating, and handling cybercrime, thus meeting the requirements of national security protection in the context of intensive international integration.

In implementing the 2025 Law on Cybersecurity, agencies, units, enterprises, organisations, and individuals across the Vietnam People's Army must thoroughly grasp their responsibilities for protecting cybersecurity in military, defence, and cipher information systems under the MND’s management. They must also strictly comply with the legal system governing the MND's functions, duties, and authority as the body responsible for assisting the Government in exercising unified State management of national defence in cyberspace, thereby successfully fulfilling the two strategic tasks of building and firmly defending the Socialist Vietnamese Fatherland in the new era.

Maj. Gen. NGUYEN VIET DUNG, MA

Director of the MND’s Department of Legal Affairs

Your Comment (0)