Vietnam has taken another significant step in strengthening its cybersecurity framework. The Government has issued three new decrees implementing the 2025 Cybersecurity Law, introducing new licensing requirements for cybersecurity and civil cryptography businesses, more detailed data localisation rules and stronger obligations for online platforms.
The three decrees are:
- Decree No. 332/2026/ND-CP on the business of cybersecurity products and services (“Decree 332”);
- Decree No. 333/2026/ND-CP detailing certain provisions and implementation measures under the Cybersecurity Law (“Decree 333”); and
- Decree No. 341/2026/ND-CP on civil cryptography activities (“Decree 341”).
Decrees 332 and 333 took effect on 19 August 2026, while Decree 341 took effect on 1 September 2026. Together, these decrees move Vietnam’s cybersecurity regime from broad statutory principles towards a more detailed and operational framework.
For businesses, the key question is whether their products, services, data practices or online platforms are now subject to additional licensing or compliance requirements.
1. Cybersecurity products and services: new licensing requirements
Decree 332 introduces a licensing regime for businesses providing specified cybersecurity products and services in Vietnam.
Regulated products include cybersecurity testing and assessment products, cybersecurity monitoring products and anti-attack or intrusion-prevention products. Regulated services include cybersecurity testing and assessment, information-security services, cybersecurity consulting, monitoring, incident response, data recovery and certain other cybersecurity services.
Businesses providing these products or services must obtain a Cybersecurity Products and Services Business Licence, which is valid for 10 years and is administered by the Ministry of Public Security (MPS).
Key licensing conditions
Applicants must generally:
- be lawfully established under Vietnamese law and comply with the applicable cybersecurity business requirements;
- have appropriate technical personnel with relevant qualifications in cybersecurity, information security, information technology or telecommunications; and
- have appropriate technical systems, facilities and technology for the relevant business activities.
For foreign-invested enterprises, the remaining investment term in Vietnam must be more than five years from the date of issuance of the business licence.
Additional requirements apply to particular services. For example, providers of cybersecurity testing and consulting services must have at least five qualified technical personnel, while cybersecurity monitoring providers must have at least 12 qualified technical personnel. For these services, the legal representative must also be a Vietnamese national.
Certain sensitive cybersecurity products, including products involving covert information collection, digital forensics, network suppression and IP-address concealment, are subject to additional restrictions. Their production, trading, import or export may be limited to entities working under assignments, orders or contracts with the competent authorities of the MPS or Ministry of National Defence for national security purposes.
Businesses importing or exporting regulated cybersecurity products must also consider separate licensing requirements and demonstrate a clear purpose and intended user, together with a commitment that the products will not prejudice national security.
2. Civil cryptography: a separate licensing regime
Decree 341 establishes a separate framework for civil cryptography products and services. Businesses providing products or services falling within the regulated categories must obtain a Civil Cryptography Products and Services Business Licence. The licence is valid for 10 years and is issued and managed by the Government Cipher Board (GCB).
The regulated products include, among others:
- cryptographic key generation, management and storage products;
- data-at-rest security products;
- internet data-exchange security products;
- IP security products; and
- certain telephone, radio and fax security products.
Regulated services include information-protection services using civil cryptography products, civil cryptography product assessment services, and cybersecurity and information-security consulting services using civil cryptography products.
Businesses must satisfy prescribed requirements relating to personnel, technical facilities and technical plans. Civil cryptography products must also satisfy applicable conformity requirements before being placed on the market. Separate import/export licences apply to products included in the relevant controlled list.
Businesses should pay particular attention to products combining civil cryptography and cybersecurity functions. Decree 341 provides for certain such products to be licensed by the MPS, following consultation with the GCB. This creates an important product-classification issue for businesses whose technology incorporates both encryption and cybersecurity functions.
3. Data localisation: more detailed requirements
Decree 333 provides more detailed rules on data storage and the establishment of a local presence by certain foreign enterprises.
The categories of data required to be stored in Vietnam include:
- personal information of service users in Vietnam; and
- specified data created by users, including service account names, service usage time, credit card information, email addresses, the most recent login and logout IP addresses, and registered telephone numbers associated with accounts or data.
The decree also expands the list of sectors relevant to foreign enterprises to expressly include online applications, alongside areas such as telecommunications, data storage and sharing, e-commerce, online payment, social networks, online games and other online information services.
For foreign enterprises, the obligation to store data and establish a branch or representative office in Vietnam is triggered in specified circumstances, including where the enterprise has received three written requests within a maximum six-month period concerning violations of the cybersecurity law but fails to provide adequate remedial measures or otherwise comply.
Where such a requirement is imposed, the enterprise must complete the required data storage and establishment of the local presence within 12 months from the MPS’s decision. The minimum data-storage period is 24 months.
Importantly, businesses have flexibility in determining the form of data storage, provided that the arrangements allow the data to be retrieved and promptly provided at the request of a competent authority and comply with applicable national standards and technical regulations.
4. Stronger obligations for online platforms
Decree 333 also strengthens obligations applicable to businesses providing services in cyberspace. Telecommunications, Internet, hosting, data-centre and certain application-service providers must respond to requests from the specialised cybersecurity authorities to block or remove unlawful content, services or applications within prescribed timeframes.
The decree also introduces escalating measures against accounts, pages, groups and content channels repeatedly used to post unlawful information. Where violations occur three or more times within 30 days, access may be restricted or the account temporarily locked for up to 60 days. Where violations occur 10 or more times within 90 days, restrictions may extend to 180 days. In certain serious or repeated cases, indefinite restrictions or account locking may apply.
These provisions place greater emphasis on proactive content monitoring and enforcement, rather than relying solely on responding to individual complaints or removal requests.
The three new decrees significantly increase the level of operational detail in Vietnam’s cybersecurity regime. For technology and digital businesses, compliance will increasingly depend not only on what the business does, but also on the technical characteristics of its products, how it handles data and how its systems respond to regulatory requirements.
Businesses operating in the cybersecurity, digital-platform, cloud, telecommunications and encryption sectors should therefore consider conducting a targeted review of their Vietnamese operations to identify any new licensing, data-localisation or operational requirements arising under the new framework.
The information provided here is for information purposes only and is not intended to constitute legal advice. Legal advice should be obtained from qualified legal counsel for all specific situations.
DFDL provides specialized legal counsel throughout the ASEAN region. Visit our Vietnam team profile for further information.