This cybersecurity law will come into effect on July 1, 2026.

SUMMARY OF THE CYBERSECURITY LAW 2025 BY CHAPTER

Chapter I – General Provisions

  • Defines the scope of regulation and subjects of application.
  • Explains key concepts: cybersecurity, data security, cyberattacks, cyberterrorism, cyberespionage, cybersecurity threats, etc.
  • Outlines the State’s policies on cybersecurity: prioritizing resources, developing human capital, international cooperation.
  • Provides principles for cybersecurity protection: compliance with the Constitution, combining cybersecurity with socio-economic development, protecting personal data.
  • Lists cybersecurity protection measures (assessment, inspection, monitoring, incident response…).
  • Specifies prohibited acts: anti‑State propaganda, historical distortion, fraud, cyberattacks, illegal intrusion, malware distribution…

Article 2. Interpretation of Terms 

In this Law, the terms below are defined as follows:

  1. Cybersecurity refers to the stability, security, and safety of cyberspace; the protection of information systems and the assurance that information, data, and activities in cyberspace do not harm national security, social order and safety, or the lawful rights and interests of agencies, organizations, and individuals.
  2. Network information security refers to ensuring the integrity, confidentiality, and availability of information in cyberspace, preventing unauthorized access, use, disclosure, modification, destruction, or other acts that threaten or harm national security, social order, and safety.
  3. Data security refers to ensuring the quality of data and data processing activities in cyberspace serving socio‑economic development and national digital transformation, preventing unauthorized access, use, disclosure, modification, destruction, or other acts that threaten or harm national security, social order, and safety.
  4. Cybersecurity protection refers to preventing, detecting, stopping, and handling acts that violate cybersecurity.
  5. Cyberspace is the environment formed by interconnected networks of information technology infrastructure, including telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, and databases; it is where people conduct social activities without being limited by space or time.
  6. National cyberspace is the portion of cyberspace under the sovereignty, jurisdiction, and control of the Socialist Republic of Vietnam.
  7. Information system is a set of hardware, software, and data established for the purpose of creating, providing, transmitting, collecting, processing, storing, and exchanging information in cyberspace.
  8. Information system administrator refers to an agency, organization, or individual with direct authority to manage an information system.
  9. Malicious software (malware) refers to software capable of causing abnormal operations in part or all of an information system, or performing unauthorized copying, modification, or deletion of information stored in the system.
  10. Malicious hardware refers to physical components intentionally designed or additionally attached outside standard hardware structures to illegally collect information or data, or to interfere with, disrupt, paralyze, or destroy computer systems or information systems.
  11. System logs are collections of records reflecting the time, user, activities, and status of a system, serving system management, monitoring, and security.
  12. Cybercrime refers to socially dangerous acts defined in the Criminal Code, committed by individuals or organizations in cyberspace using information technology or electronic means.
  13. Cyberattack refers to acts carried out in cyberspace using information technology or electronic means to appropriate information, disrupt, interrupt, paralyze operations, destroy, or take control of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, or electronic devices.
  14. Cyberterrorism refers to acts carried out in cyberspace using information technology or electronic means with the intent to cause public fear or destabilize political security.
  15. Cyberespionage refers to acts carried out in cyberspace using information technology or electronic means to secretly infiltrate and appropriate, collect, or copy information classified as state secrets or important data of agencies, organizations, or individuals, with the intent to harm national security, social order, and safety.
  16. Cybersecurity threat refers to a state of cyberspace in which signs appear indicating potential violations of national security, causing serious harm to social order and safety, or to the lawful rights and interests of agencies, organizations, and individuals.
  17. Cybersecurity incident refers to unexpected events occurring in cyberspace that violate national security, social order and safety, or the lawful rights and interests of agencies, organizations, and individuals.
  18. Dangerous cybersecurity situation refers to a state or development in cyberspace involving elements of attack, intrusion, provocation, information leakage, information loss, or other acts that seriously threaten national security, social order and safety, or the lawful rights and interests of agencies, organizations, and individuals.
  19. Digital account refers to information used for authentication, verification, and authorization when using applications and services in cyberspace.
  20. Civil cryptography refers to cryptographic techniques and cryptographic products used to secure or authenticate information not classified as state secrets, ensuring information security for agencies, organizations, and individuals.
  21. Cybersecurity products refer to hardware and software designed to protect cybersecurity, network information security, data security, information, data, information systems, and information technology infrastructure.
  22. Cybersecurity services refer to services provided to protect cybersecurity, network information security, data security, information, data, information systems, and information technology infrastructure.
  23. Core information systems refer to information systems that use core cryptography to protect information classified as state secrets, serving specialized cipher operations and directly managed and operated by cipher organizations.
Article 7. Prohibited Acts Related to Cybersecurity 
1. Posting or disseminating the following types of information in cyberspace:
a) Propaganda against the Socialist Republic of Vietnam, including: distorting or defaming the people’s government; psychological warfare; inciting aggressive war; creating division or hatred among ethnic groups, religions, or peoples of other countries; insulting the nation, national flag, national emblem, national anthem, great figures, leaders, national heroes.
b) Distorting history, denying revolutionary achievements, undermining national unity, insulting religions, gender discrimination, racial discrimination.
c) Fabricating, slandering, or spreading false information that infringes upon the dignity, honor, or reputation of others, or causes harm to the lawful rights and interests of agencies, organizations, or individuals.

d) Disseminating false information that causes public panic, damages socio‑economic activities, obstructs normal operations of state agencies or public officials, or infringes upon lawful rights and interests of agencies, organizations, or individuals; fabricating false information about products, goods, currency, bonds, bills, treasury notes, checks, and other valuable papers; spreading false information in finance, banking, e‑commerce, multi‑level marketing, or securities.

 

2. Committing the following acts in cyberspace:
a) Organizing, operating, colluding, inciting, bribing, deceiving, luring, training, or instructing others to act against the Socialist Republic of Vietnam.
b) Inciting, calling for, mobilizing, threatening, or dividing people to conduct armed activities or use violence against the people’s government; calling for or inciting gatherings that cause disorder, resist law enforcement, or obstruct operations of agencies or organizations, thereby destabilizing security and order.
c) Appropriating, trading, storing, or intentionally disclosing state secrets, work secrets, business secrets; appropriating, trading, storing, or intentionally disclosing personal secrets, family secrets, or private life information that affects the dignity, honor, or lawful rights of agencies, organizations, or individuals; intentionally eavesdropping, recording, or filming conversations in cyberspace without permission; disclosing information about civil cryptographic products or customers using such products; using or trading civil cryptographic products of unclear origin.
d) Engaging in prostitution, social evils, human trafficking, trafficking of human organs; disseminating obscene or depraved materials; inciting or promoting violence, immoral lifestyles, deviant behaviors, or acts that undermine cultural values, social ethics, or community health.
e) Committing fraud to appropriate assets; organizing gambling or online gambling; stealing international telecommunications charges via the Internet; promoting, advertising, or trading prohibited goods or services; violating copyright or intellectual property rights in cyberspace.
f) Impersonating websites of agencies, organizations, or individuals; forging, circulating, stealing, trading, collecting, or illegally exchanging credit card information, bank accounts, encrypted assets, or digital assets of others; issuing, providing, or using illegal payment instruments; forging documents of agencies or organizations.
g) Using artificial intelligence or new technologies to impersonate videos, images, or voices of others in violation of the law; creating, posting, or disseminating information specified in Clause 1 of this Article.
h) Collecting, using, disseminating, exchanging, transferring, or trading personal data of others illegally.
i) Instructing, inciting, luring, or encouraging others to commit crimes or violate the law.
k) Conducting other acts in cyberspace using information technology or electronic means that violate national security, social order, or safety.
3. Conducting cyberattacks, cyberterrorism, cyberespionage, cybercrime, or high‑tech crime; causing incidents, attacks, intrusions, taking control, altering, disrupting, paralyzing, or destroying information systems.
4. Producing or using tools, devices, or software, or committing acts that obstruct, disrupt, or spread spam emails, spam messages, spam calls, or harmful software that affects telecommunications networks, the Internet, computer networks, information systems, or information processing and control systems.
5. Illegally infiltrating telecommunications networks, computer networks, information systems, information processing and control systems, databases, or electronic devices of others.
6. Resisting or obstructing cybersecurity protection forces; attacking or illegally disabling cybersecurity protection measures.
7. Abusing or misusing cybersecurity protection activities to infringe upon national sovereignty, interests, security, social order and safety, or lawful rights and interests of agencies, organizations, or individuals, or for personal gain.

8. Other acts violating the provisions of this Law.

 

Chapter II – Cybersecurity Protection for Information Systems

  • Classifies information systems into 5 levels based on potential damage if incidents occur.
  • Identifies information systems critical to national security (military, diplomacy, energy, finance, healthcare…).
  • Defines tasks and measures for cybersecurity protection for each system level.
  • Responsibilities of administrators of critical information systems: periodic inspection, monitoring, incident response.
  • Responsibilities of the Ministry of Public Security, Ministry of National Defense, and Government Cipher Committee in assessment and supervision.
  • Cybersecurity inspection for systems not classified as critical.
  • Chapter III – Prevention and Handling of Acts Violating Cybersecurity


Chapter III – Prevention and Handling of Acts Violating Cybersecurity

  • Identifies types of information violating national security: anti‑State content, undermining unity, defamation, disturbing public order.
  • Defines illegal acts using IT: impersonation, fraud, gambling, data trading, illegal online platforms…
  • Responsibilities of enterprises and system administrators in blocking and removing violating information.
  • Preventing cyberespionage; protecting state secrets and personal privacy.
  • Protecting children online: content control, preventing exploitation.
  • Preventing malware, cyberattacks, cyberterrorism.
  • Handling dangerous cybersecurity situations (large‑scale attacks, threats to sovereignty).
  • Cybersecurity defense and prevention of information conflicts.

Chapter IV – Cybersecurity Protection Activities

  • Implementing cybersecurity protection in state agencies: regulations, technology application, personnel training.
  • Protecting national cyberspace infrastructure and international gateways.
  • Ensuring information security: account verification, providing data to authorities, storing data in Vietnam.
  • Ensuring data security: procedures, standards, personnel control, risk assessment, cross‑border data transfer control.

Chapter V – Standards, Technical Regulations, Cybersecurity Products and Services

  • Defines standards and technical regulations for cybersecurity products and services.
  • Certification of conformity and compliance for products and services.
  • Classification of cybersecurity products (civil cryptography, monitoring, anti‑attack…).
  • Classification of cybersecurity services (assessment, consulting, monitoring, incident response…).
  • Regulations on cybersecurity business: licensing, quality assurance, customer data protection.

Chapter VI – Forces and Conditions Ensuring Cybersecurity

  • Defines cybersecurity forces: Ministry of Public Security, Ministry of National Defense, Government Cipher Committee, and units in ministries and organizations.
  • Policies for training and developing cybersecurity human resources.
  • Advanced training for administrators of high‑level information systems.
  • Public cybersecurity awareness programs.
  • Research and development of cybersecurity technologies; enhancing national autonomy.
  • Regulations on cybersecurity funding (minimum 15% of digital transformation budget).

Chapter VII – Responsibilities of Agencies, Organizations, and Individuals

  • The Government uniformly manages cybersecurity nationwide.
  • Ministry of Public Security is the focal point; Ministry of National Defense manages military‑related cybersecurity.
  • Responsibilities of system administrators: monitoring connections, reporting incidents.
  • Responsibilities of service providers: risk warnings, incident response, IP identification, data provision upon request.
  • Responsibilities of individuals: securing accounts, providing information when required, complying with cybersecurity laws.

Chapter VIII – Implementation Provisions

Amends and supplements multiple related laws to align with the concept of “cybersecurity.”

The Law takes effect on July 1, 2026.

The 2015 Cyberinformation Security Law and the 2018 Cybersecurity Law are repealed.

Transitional provisions for system classification and business licenses.