top of page

2025 Cybersecurity Law Compliance: What should businesses do?

To achieve compliance with the 2025 Cybersecurity Law, businesses should not simply purchase another firewall, antivirus application, or monitoring solution. They need to identify the obligations that apply to them, inventory their systems and data, assign responsibilities, conduct a gap assessment, remediate risks, and maintain evidence showing that their security measures are operating effectively.

Cybersecurity Law No. 116/2025/QH15 was enacted on December 10, 2025, and will take effect on July 1, 2026. Therefore, the term “2025 Cybersecurity Law compliance” should be understood as the process of preparing for and implementing the requirements of the law enacted in 2025, rather than as a compliance program limited to the 2025 calendar year.

2025-cybersecurity-law-in-vietnam
2025 cybersecurity law in Vietnam

Because the applicable requirements may differ depending on the industry, types of systems, data-processing activities, and service-delivery model, businesses should combine a legal assessment with a technical assessment. The checklist below provides a practical implementation framework and is not a substitute for legal advice tailored to a specific organization or situation.

1. Determine which obligations apply to the business

The first step toward compliance with the 2025 Cybersecurity Law is not deploying technology. It is accurately identifying the systems, platforms, and activities operated by the business that may fall within the law’s scope.

The business should establish a review team comprising representatives from senior management, legal, information technology, information security, data governance, and critical business functions. At a minimum, the team should answer the following questions:

  • What information systems does the business currently operate?

  • Which systems have a direct impact on business operations?

  • Does the business provide Internet-based services or digital platforms?

  • What types of data are being collected, stored, and shared?

  • Is the data stored in Vietnam, overseas, or across multiple cloud environments?

  • Which internal or external parties have access to the systems and data?

  • Are any foreign service providers or third parties involved in processing the data?

  • Does the business operate in an industry subject to additional sector-specific requirements?

The output of this step should be a documented compliance scope, rather than a general assumption that “all company systems are in scope.”

Businesses should also avoid combining the Cybersecurity Law with every obligation relating to data into a single undifferentiated requirement. A system may simultaneously be subject to the Cybersecurity Law, the Data Law, personal data protection regulations, and sector-specific rules. Businesses should therefore develop a consolidated obligations matrix while clearly identifying the legal basis for each requirement.

2. Inventory systems, data and service providers

A business cannot protect or demonstrate control over assets that it has not fully identified.

To prepare for compliance with the 2025 Cybersecurity Law, businesses should create and maintain an inventory covering at least:

  • Physical and virtual servers.

  • Cloud systems, SaaS platforms, and outsourced applications.

  • Websites, mobile applications, APIs, and customer portals.

  • Network devices, firewalls, VPNs, and remote-access equipment.

  • Computers, mobile devices, and user accounts.

  • Databases and storage repositories.

  • Email, identity, and authentication systems.

  • Software developed internally by the business.

  • Service providers authorized to access systems or data.

Each asset should have an identified owner, purpose, criticality rating, data classification, storage location, and responsible operating party.

For data, the business should develop data-flow diagrams identifying where data is collected, which systems it passes through, how long it is retained, with whom it is shared, and how it is deleted.

The inventory should not be treated as a one-time exercise. It must be updated whenever the business introduces a new application, migrates to the cloud, integrates an API, changes service providers, or deploys an AI tool.

3. Establish cybersecurity responsibilities and governance mechanisms

Compliance cannot be treated solely as the responsibility of the IT department. IT may operate the technology, but it cannot independently determine all legal requirements, risk-acceptance levels, or responses to incidents affecting customers.

2025-cybersecurity-law-process
Complying with the 2025 cybersecurity law is not just the responsibility of one group

Businesses should clearly define the following responsibilities.

Senior management

  • Approve policies and risk-acceptance levels.

  • Allocate appropriate resources.

  • Monitor significant risks.

  • Decide how to address deficiencies that cannot be remediated immediately.

Legal or compliance department

  • Identify applicable legal obligations.

  • Monitor changes in laws and regulations.

  • Review contracts with service providers.

  • Advise on obligations to cooperate, notify relevant parties, or provide information when an event occurs.

IT and Information security teams

  • Implement technical controls.

  • Monitor vulnerabilities, configurations, and logs.

  • Detect, investigate, and respond to incidents.

  • Maintain technical evidence.

Business departments

  • Identify critical data and business processes.

  • Comply with system access and acceptable-use policies.

  • Participate in risk assessments.

  • Report unusual or suspicious events.

At a minimum, the business should issue an overarching cybersecurity policy and supporting procedures for account management, vulnerability management, backups, incident response, service-provider management, and change management.

4. Implement technical measures based on risk

Laws and policies are meaningful only when translated into protective measures that can be tested and verified.

Access control

Businesses must ensure that users receive only the access rights required for their work. Administrative accounts, shared accounts, and service-provider accounts should be subject to stricter controls than ordinary user accounts.

Priority measures should include:

  • Applying multi-factor authentication to critical accounts.

  • Separating administrative accounts from accounts used for everyday work.

  • Reviewing access rights periodically.

  • Revoking accounts immediately when employees leave or change roles.

  • Monitoring unusual login activity.

  • Restricting the use of shared accounts.

Vulnerability and configuration management

Businesses should have a process for discovering, assessing, and remediating vulnerabilities according to risk. Running a scanning tool without tracking remediation does not create meaningful compliance value.

The process should define:

  • Which systems are scanned.

  • How frequently assessments are performed.

  • How severity is classified.

  • The applicable remediation deadlines.

  • The person responsible for remediation.

  • The circumstances in which retesting is required.

For websites, applications, APIs, cloud environments, or critical systems, businesses may conduct penetration testing to determine whether identified weaknesses can be exploited under realistic conditions.

Penetration testing is only one component of a security program. It does not replace governance, monitoring, training, backups, or incident response.

Data protection

Businesses should determine which data must be encrypted while stored or transmitted, who is authorized to decrypt it, and how encryption keys are managed.

Measures to consider include:

  • Encrypting critical data.

  • Applying role-based access controls.

  • Restricting data downloads to personal devices.

  • Controlling the external sharing of data.

  • Maintaining backups separate from the primary system.

  • Testing data-restoration capabilities.

  • Recording access to and modification of data.

Businesses should not assume that using cloud services transfers all responsibility to the cloud provider. The business remains responsible for managing accounts, configurations, access rights, data, and contractual obligations within its area of control.

Logging and monitoring

Businesses should determine which events must be logged, where logs are stored, who may access them, and how alerts are generated for suspicious activity.

Logging should cover critical systems and events such as:

  • Login and authentication activity.

  • Administrative-account activity.

  • Configuration changes.

  • Database access.

  • Endpoint security events.

  • Firewall, VPN, and cloud activity.

  • Actions performed through privileged service-provider accounts.

Maintaining logs without monitoring them, or being unable to retrieve them during an incident, significantly reduces the organization’s ability to investigate events and demonstrate that controls have been operating.

5. Establish a cybersecurity incident response process

Compliance with the 2025 Cybersecurity Law requires businesses to prepare in advance for detecting, receiving, classifying, and responding to incidents. Responsibilities should not be assigned only after an attack has already occurred.

The incident response plan should clearly answer the following questions:

  1. Who is the primary point of contact for receiving alerts?

  2. Which criteria are used to classify an incident?

  3. Who has the authority to isolate a server or suspend an account?

  4. When should the crisis management team be activated?

  5. Who is responsible for collecting and preserving evidence?

  6. At what stage should the legal department become involved?

  7. Who communicates with customers, partners, and competent authorities?

  8. In what order should systems be restored?

  9. Who is responsible for conducting the post-incident root-cause assessment and tracking remediation?

Businesses should maintain emergency contact lists, escalation diagrams, and response playbooks for ransomware, data breaches, account compromise, website attacks, lost devices, and service-provider incidents.

The plan must be tested through exercises. A procedure that has never been tested may fail during an actual incident.

6. Control service-provider and supply-chain risks

Many businesses maintain relatively secure internal systems but remain exposed through IT partners, software developers, cloud providers, or remote-support accounts.

To comply effectively with the 2025 Cybersecurity Law, businesses should integrate security requirements throughout the entire service-provider lifecycle.

Before signing a contract, the business should assess:

  • Which systems or data the provider will access.

  • Where the data will be stored.

  • Whether subcontractors will be used.

  • Whether the provider adequately controls privileged accounts.

  • Whether backup and restoration mechanisms are available.

  • Whether logs can be provided during an incident.

  • Whether the provider has an incident-notification process.

Contracts should clearly define:

  • The permitted scope of data processing.

  • Minimum security requirements.

  • Incident-notification timeframes.

  • Responsibilities for supporting investigations.

  • Audit rights or rights to request evidence.

  • Conditions governing the use of subcontractors.

  • Procedures for returning or deleting data.

  • Methods for revoking accounts when the contract ends.

The IT department should not independently approve all service-provider risks. Arrangements involving critical data should also be reviewed by legal, information security, and the relevant business process owner.

7. Train employees and verify implementation

Employees directly use email, data, accounts, and systems. Compliance therefore cannot be demonstrated solely through signed policy acknowledgements.

The training program should be tailored to different roles:

  • General employees: phishing, passwords, data handling, and event reporting.

  • Managers: access approvals, risk management, and incident handling.

  • IT personnel: configuration, patching, logging, backups, and administrative accounts.

  • Developers: secure software development and source-code management.

  • Human resources personnel: employee account lifecycle management.

  • Legal personnel: legal obligations and incident coordination.

  • Senior management: governance responsibilities and decision-making.

Businesses may refer to IPSIP’s cybersecurity training and consulting services when developing content appropriate for different employee groups and internal policies.

After training, the business should assess employee understanding and behavioral changes through tests, phishing simulations, incident-response exercises, or evaluations of policy implementation.

8. Maintain evidence of compliance

A common gap is that a business may have implemented certain security measures but cannot provide records showing who performed them, when they were performed, and what the results were.

The compliance documentation set should include:

Control Area

Records or Evidence to Maintain

Governance

Policies, responsibility-assignment decisions, approval records

Assets

System inventories, network diagrams, application inventories

Data

Data-flow diagrams, data inventories, access permissions

Accounts

Access lists, review records, account-revocation records

Vulnerabilities

Scan reports, penetration-test reports, remediation plans, retest results

Incidents

Incident response plans, incident logs, exercise reports

Backups

Backup policies, backup logs, restoration-test results

Service Providers

Assessment forms, contracts, SLAs, control evidence

Training

Training materials, attendance lists, test results

Monitoring

Logs, alerts, remediation tickets, and periodic reports

Records must reflect actual operations. Drafting policies without operational evidence may create the appearance of compliance on paper but does not meaningfully reduce risk.

9. Conduct a gap assessment and develop a remediation plan

After determining the applicable scope, the business should compare the applicable requirements with its current controls.

The gap assessment should be conducted across three layers:

  • Legal layer: Has the business fully identified its applicable obligations?

  • Governance layer: Are the necessary policies, responsibilities, and procedures in place?

  • Technical layer: Are the controls configured and operating effectively?

Each deficiency should be recorded together with:

  • The affected system or process.

  • The related obligation.

  • The business risk.

  • The priority level.

  • The responsible person.

  • The completion deadline.

  • The evidence required to close the item.

Businesses do not necessarily need to address every issue simultaneously. Priority should be given to deficiencies that could result in loss of account control, data exposure, disruption to critical systems, or an inability to detect and respond to incidents.

Small and medium-sized businesses without a dedicated security team can begin with a business cybersecurity assessment to identify priority gaps before investing in additional technology.

2025 Cybersecurity Law Compliance Checklist for Businesses

Businesses can use the following checklist to conduct an initial readiness review:

  • Applicable laws, regulations, and obligations have been identified.

  • A compliance team has been established.

  • Systems, applications, data, and service providers have been inventoried.

  • An accountable owner has been assigned to each critical system.

  • A cybersecurity policy has been issued.

  • Account and access-right management controls have been implemented.

  • Multi-factor authentication is enabled for critical accounts.

  • Vulnerability and patch-management procedures are in place.

  • Critical systems undergo periodic security assessments.

  • Backup and restoration-testing mechanisms have been implemented.

  • Logging is enabled on critical systems.

  • A person or service provider is responsible for monitoring alerts.

  • An incident response plan has been developed and tested.

  • Service-provider contracts contain security provisions.

  • Employees have received role-based training.

  • A remediation plan has been established and tracked through completion.

  • Compliance documentation is centrally managed and periodically updated.

This checklist provides only an initial indication of readiness. Every “Yes” answer should be supported by corresponding documentation, configurations, logs, or operational evidence.

5 common misconceptions about 2025 Cybersecurity Law Compliance

1. Having ISO 27001 certification means the business is already compliant

ISO 27001 can provide a foundation for information security management, but the business must still map its controls against each applicable legal obligation.

2. Penetration testing eliminates the need for a compliance assessment

Penetration testing focuses on whether technical weaknesses can be exploited. A compliance assessment also covers governance, procedures, data, service providers, training, and supporting evidence.

3. A Firewall and antivirus software are sufficient

These tools do not replace account management, log monitoring, data protection, incident response, or third-party risk controls.

4. Using cloud services makes the provider fully responsible

Cloud services generally operate under a shared-responsibility model. The business remains responsible for controlling accounts, configurations, data, and how the service is used.

5. Compliance can be maintained after completing a one-time project

Systems, data, personnel, service providers, and threats continually change. Businesses must conduct periodic assessments and additional reviews following significant changes.

Compliance with the 2025 Cybersecurity Law is not achieved by purchasing a product or completing a set of documents. It is a continuous process involving scope identification, asset management, data protection, access control, monitoring, incident response, service-provider management, and the maintenance of evidence.

Businesses should begin with a gap assessment to determine what is missing from their current environment, which risks should be prioritized, and which measures genuinely require investment. This approach helps prevent businesses from purchasing numerous tools while remaining unable to demonstrate compliance or effective system protection.

IPSIP can help businesses review their current environments, assess governance and technical gaps, determine remediation priorities, and develop an improvement roadmap appropriate for their scale of operations. Businesses can schedule a consultation with IPSIP to determine the scope of an initial assessment.

-------------

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page