Vietnam Law on Cybersecurity (No. 116/2025/QH15)
Vietnam's Law on Cybersecurity No. 116/2025/QH15, in force since 1 July 2026, replaced the 2018 Law on Cybersecurity and the 2015 Law on Cyberinformation Security, with the Ministry of Public Security as the lead authority and Decree 333/2026 (August 2026) filling in detail. Information systems are classified into five levels, and systems critical to national security need appraisal, certification and annual self-inspection. Service providers must authenticate accounts, answer user-data requests within 24 hours and take down unlawful content within 24 hours, keep logs for 12 months, identify IP addresses, store listed Vietnamese user data in Vietnam and, for foreign providers, open a local office when required. Legacy systems must meet the new measures by 1 July 2027.
Vietnam Law on Cybersecurity (No. 116/2025/QH15) is a compliance framework from Vietnam with 5 domains and 19 controls that map to 197 other frameworks. The largest domains are Duties of service providers in cyberspace (Articles 25, 41; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15) (5 controls), Handling threats, incidents and unlawful content (Chapter III) – Vietnam Law on Cybersecurity (No. 116/2025/QH15) (4 controls), Products, services, infrastructure and users (Articles 7, 23, 24, 29, 42) – Vietnam Law on Cybersecurity (No. 116/2025/QH15) (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Data security, localisation and logs (Articles 25, 26; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)
| Code | Title |
|---|---|
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-25-LOC | Store Vietnamese users' data in Vietnam; foreign providers in listed sectors must store it and open a branch or office once the Minister so decides |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-25-LOG | Keep system logs retrievable for at least 12 months and retain user data after users leave, for the legal period |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-26 | Assure data security: policies and procedures, cryptography, control of data-handling staff, periodic risk assessment and checks on cross-border transfers |
Duties of service providers in cyberspace (Articles 25, 41; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)
| Code | Title |
|---|---|
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-25-ACCT | Authenticate users at account registration by Vietnamese mobile number or personal ID and let only verified accounts post |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-25-REQ | Give user information to the specialised force within 24 hours (3 in emergencies) and remove unlawful content or services within 24 hours (6 in emergencies) |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-41-COOP | Build the connections and transmission links the specialised force needs for investigations |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-41-IP | Identify the IP addresses of service users and keep 12 months of IP assignment logs for the specialised force |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-41-IR | Warn users of risks, keep an emergency response plan, and on an incident apply it and report to the specialised force at the same time |
Handling threats, incidents and unlawful content (Chapter III) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)
| Code | Title |
|---|---|
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-12-15 | Inspect systems for malware, malicious hardware and vulnerabilities, stop espionage and data leaks, and notify the specialised force of violations |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-14-16 | Prevent, detect, block and remove prohibited content, and deploy systems against child-abusive content |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-17-18 | Prevent and block malware and cyberattacks; email and storage services filter malware and ISPs stop its spread |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-20 | Report dangerous cybersecurity situations and signs of cyber-terrorism at once and start emergency response |
Products, services, infrastructure and users (Articles 7, 23, 24, 29, 42) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)
| Code | Title |
|---|---|
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-23-24 | State bodies: set network rules, security and incident plans and staff training; infrastructure and gateway operators: submit to inspection and enable state measures |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-29 | Hold a licence to trade cybersecurity products and services and keep products conforming to declared standards |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-42 | Users: keep digital account credentials confidential and report cybersecurity information |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-7 | Do not commit the prohibited acts, including unlawful trading in personal data and AI-fabricated likenesses |
Protection of information systems (Chapters II and VII) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)
| Code | Title |
|---|---|
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-40 | Connect monitoring and anti-malware systems to the national or provincial cybersecurity centre and report incidents to the specialised agency |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-8-10 | Classify each information system into one of five levels and carry out the protection tasks and measures that level requires |
| vietnam-law-on-cybersecurity-no-1162025qh15::VNCS-9-11 | For systems critical to national security: appraisal and certification before use, annual self-inspection reported before October, monitoring and incident plans |
Your Compliance Coverage
If you comply with Vietnam Law on Cybersecurity (No. 116/2025/QH15), you already cover:
New Hampshire Data Privacy Act
13%
3 controls mapped
Compare →Australian Privacy Principles (APPs)
13%
3 controls mapped
Compare →Azerbaijan Law on Personal Data (2010)
13%
3 controls mapped
Compare →+ 194 more: Armenia Law on Protection of Personal Data (2015) (13%), Albania Law No. 124/2024 on Personal Data Protection (13%)
See all 197 mapped frameworks ↓Maps to 197 other frameworks
Coverage is not the same as your position
This page shows what Vietnam Law on Cybersecurity (No. 116/2025/QH15) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Vietnam Law on Cybersecurity (No. 116/2025/QH15) and who does it apply to?
Vietnam Law on Cybersecurity (No. 116/2025/QH15) is a compliance framework from Vietnam with 5 domains and 19 controls. Vietnam's Law on Cybersecurity No. 116/2025/QH15, in force since 1 July 2026, replaced the 2018 Law on Cybersecurity and the 2015 Law on Cyberinformation Security, with the Ministry of Public Security as the lead authority and Decree 333/2026 (August 2026) filling in detail. Information systems are classified into five levels, and systems critical to national security need appraisal, certification and annual self-inspection. Service providers must authenticate accounts, answer user-data requests within 24 hours and take down unlawful content within 24 hours, keep logs for 12 months, identify IP addresses, store listed Vietnamese user data in Vietnam and, for foreign providers, open a local office when required. Legacy systems must meet the new measures by 1 July 2027. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Vietnam Law on Cybersecurity (No. 116/2025/QH15) actually require?
Vietnam Law on Cybersecurity (No. 116/2025/QH15) has 19 controls organised across 5 domains. The largest domains are Duties of service providers in cyberspace (Articles 25, 41; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15) (5 controls), Handling threats, incidents and unlawful content (Chapter III) – Vietnam Law on Cybersecurity (No. 116/2025/QH15) (4 controls), Products, services, infrastructure and users (Articles 7, 23, 24, 29, 42) – Vietnam Law on Cybersecurity (No. 116/2025/QH15) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Vietnam Law on Cybersecurity (No. 116/2025/QH15) do I already cover?
Vietnam Law on Cybersecurity (No. 116/2025/QH15) maps to 197 other compliance frameworks. The top mapping partners are New Hampshire Data Privacy Act (13% coverage), Australian Privacy Principles (APPs) (13% coverage), Azerbaijan Law on Personal Data (2010) (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Vietnam Law on Cybersecurity (No. 116/2025/QH15)?
Start your Vietnam Law on Cybersecurity (No. 116/2025/QH15) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Vietnam Law on Cybersecurity (No. 116/2025/QH15) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 19 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required