SUMMARY OF THE CYBERSECURITY LAW 2025 BY CHAPTER
Chapter I – General Provisions
- Defines the scope of regulation and subjects of application.
- Explains key concepts: cybersecurity, data security, cyberattacks, cyberterrorism, cyberespionage, cybersecurity threats, etc.
- Outlines the State’s policies on cybersecurity: prioritizing resources, developing human capital, international cooperation.
- Provides principles for cybersecurity protection: compliance with the Constitution, combining cybersecurity with socio-economic development, protecting personal data.
- Lists cybersecurity protection measures (assessment, inspection, monitoring, incident response…).
- Specifies prohibited acts: anti‑State propaganda, historical distortion, fraud, cyberattacks, illegal intrusion, malware distribution…
Article 2. Interpretation of Terms
In this Law, the terms below are defined as follows:
- Cybersecurity refers to the stability, security, and safety of cyberspace; the protection of information systems and the assurance that information, data, and activities in cyberspace do not harm national security, social order and safety, or the lawful rights and interests of agencies, organizations, and individuals.
- Network information security refers to ensuring the integrity, confidentiality, and availability of information in cyberspace, preventing unauthorized access, use, disclosure, modification, destruction, or other acts that threaten or harm national security, social order, and safety.
- Data security refers to ensuring the quality of data and data processing activities in cyberspace serving socio‑economic development and national digital transformation, preventing unauthorized access, use, disclosure, modification, destruction, or other acts that threaten or harm national security, social order, and safety.
- Cybersecurity protection refers to preventing, detecting, stopping, and handling acts that violate cybersecurity.
- Cyberspace is the environment formed by interconnected networks of information technology infrastructure, including telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, and databases; it is where people conduct social activities without being limited by space or time.
- National cyberspace is the portion of cyberspace under the sovereignty, jurisdiction, and control of the Socialist Republic of Vietnam.
- Information system is a set of hardware, software, and data established for the purpose of creating, providing, transmitting, collecting, processing, storing, and exchanging information in cyberspace.
- Information system administrator refers to an agency, organization, or individual with direct authority to manage an information system.
- Malicious software (malware) refers to software capable of causing abnormal operations in part or all of an information system, or performing unauthorized copying, modification, or deletion of information stored in the system.
- Malicious hardware refers to physical components intentionally designed or additionally attached outside standard hardware structures to illegally collect information or data, or to interfere with, disrupt, paralyze, or destroy computer systems or information systems.
- System logs are collections of records reflecting the time, user, activities, and status of a system, serving system management, monitoring, and security.
- Cybercrime refers to socially dangerous acts defined in the Criminal Code, committed by individuals or organizations in cyberspace using information technology or electronic means.
- Cyberattack refers to acts carried out in cyberspace using information technology or electronic means to appropriate information, disrupt, interrupt, paralyze operations, destroy, or take control of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, or electronic devices.
- Cyberterrorism refers to acts carried out in cyberspace using information technology or electronic means with the intent to cause public fear or destabilize political security.
- Cyberespionage refers to acts carried out in cyberspace using information technology or electronic means to secretly infiltrate and appropriate, collect, or copy information classified as state secrets or important data of agencies, organizations, or individuals, with the intent to harm national security, social order, and safety.
- Cybersecurity threat refers to a state of cyberspace in which signs appear indicating potential violations of national security, causing serious harm to social order and safety, or to the lawful rights and interests of agencies, organizations, and individuals.
- Cybersecurity incident refers to unexpected events occurring in cyberspace that violate national security, social order and safety, or the lawful rights and interests of agencies, organizations, and individuals.
- Dangerous cybersecurity situation refers to a state or development in cyberspace involving elements of attack, intrusion, provocation, information leakage, information loss, or other acts that seriously threaten national security, social order and safety, or the lawful rights and interests of agencies, organizations, and individuals.
- Digital account refers to information used for authentication, verification, and authorization when using applications and services in cyberspace.
- Civil cryptography refers to cryptographic techniques and cryptographic products used to secure or authenticate information not classified as state secrets, ensuring information security for agencies, organizations, and individuals.
- Cybersecurity products refer to hardware and software designed to protect cybersecurity, network information security, data security, information, data, information systems, and information technology infrastructure.
- Cybersecurity services refer to services provided to protect cybersecurity, network information security, data security, information, data, information systems, and information technology infrastructure.
- Core information systems refer to information systems that use core cryptography to protect information classified as state secrets, serving specialized cipher operations and directly managed and operated by cipher organizations.
d) Disseminating false information that causes public panic, damages socio‑economic activities, obstructs normal operations of state agencies or public officials, or infringes upon lawful rights and interests of agencies, organizations, or individuals; fabricating false information about products, goods, currency, bonds, bills, treasury notes, checks, and other valuable papers; spreading false information in finance, banking, e‑commerce, multi‑level marketing, or securities.
8. Other acts violating the provisions of this Law.
Chapter II – Cybersecurity Protection for Information Systems
- Classifies information systems into 5 levels based on potential damage if incidents occur.
- Identifies information systems critical to national security (military, diplomacy, energy, finance, healthcare…).
- Defines tasks and measures for cybersecurity protection for each system level.
- Responsibilities of administrators of critical information systems: periodic inspection, monitoring, incident response.
- Responsibilities of the Ministry of Public Security, Ministry of National Defense, and Government Cipher Committee in assessment and supervision.
- Cybersecurity inspection for systems not classified as critical.
- Chapter III – Prevention and Handling of Acts Violating Cybersecurity
Chapter III – Prevention and Handling of Acts Violating Cybersecurity
- Identifies types of information violating national security: anti‑State content, undermining unity, defamation, disturbing public order.
- Defines illegal acts using IT: impersonation, fraud, gambling, data trading, illegal online platforms…
- Responsibilities of enterprises and system administrators in blocking and removing violating information.
- Preventing cyberespionage; protecting state secrets and personal privacy.
- Protecting children online: content control, preventing exploitation.
- Preventing malware, cyberattacks, cyberterrorism.
- Handling dangerous cybersecurity situations (large‑scale attacks, threats to sovereignty).
- Cybersecurity defense and prevention of information conflicts.
Chapter IV – Cybersecurity Protection Activities
- Implementing cybersecurity protection in state agencies: regulations, technology application, personnel training.
- Protecting national cyberspace infrastructure and international gateways.
- Ensuring information security: account verification, providing data to authorities, storing data in Vietnam.
- Ensuring data security: procedures, standards, personnel control, risk assessment, cross‑border data transfer control.
Chapter V – Standards, Technical Regulations, Cybersecurity Products and Services
- Defines standards and technical regulations for cybersecurity products and services.
- Certification of conformity and compliance for products and services.
- Classification of cybersecurity products (civil cryptography, monitoring, anti‑attack…).
- Classification of cybersecurity services (assessment, consulting, monitoring, incident response…).
- Regulations on cybersecurity business: licensing, quality assurance, customer data protection.
Chapter VI – Forces and Conditions Ensuring Cybersecurity
- Defines cybersecurity forces: Ministry of Public Security, Ministry of National Defense, Government Cipher Committee, and units in ministries and organizations.
- Policies for training and developing cybersecurity human resources.
- Advanced training for administrators of high‑level information systems.
- Public cybersecurity awareness programs.
- Research and development of cybersecurity technologies; enhancing national autonomy.
- Regulations on cybersecurity funding (minimum 15% of digital transformation budget).
Chapter VII – Responsibilities of Agencies, Organizations, and Individuals
- The Government uniformly manages cybersecurity nationwide.
- Ministry of Public Security is the focal point; Ministry of National Defense manages military‑related cybersecurity.
- Responsibilities of system administrators: monitoring connections, reporting incidents.
- Responsibilities of service providers: risk warnings, incident response, IP identification, data provision upon request.
- Responsibilities of individuals: securing accounts, providing information when required, complying with cybersecurity laws.
Chapter VIII – Implementation Provisions
Amends and supplements multiple related laws to align with the concept of “cybersecurity.”
The Law takes effect on July 1, 2026.
The 2015 Cyberinformation Security Law and the 2018 Cybersecurity Law are repealed.
Transitional provisions for system classification and business licenses.