2025 Cybersecurity Law Compliance: What should businesses do?
- Hung Pham

- Jul 22
- 9 min read
To achieve compliance with the 2025 Cybersecurity Law, businesses should not simply purchase another firewall, antivirus application, or monitoring solution. They need to identify the obligations that apply to them, inventory their systems and data, assign responsibilities, conduct a gap assessment, remediate risks, and maintain evidence showing that their security measures are operating effectively.
Cybersecurity Law No. 116/2025/QH15 was enacted on December 10, 2025, and will take effect on July 1, 2026. Therefore, the term “2025 Cybersecurity Law compliance” should be understood as the process of preparing for and implementing the requirements of the law enacted in 2025, rather than as a compliance program limited to the 2025 calendar year.

Because the applicable requirements may differ depending on the industry, types of systems, data-processing activities, and service-delivery model, businesses should combine a legal assessment with a technical assessment. The checklist below provides a practical implementation framework and is not a substitute for legal advice tailored to a specific organization or situation.
1. Determine which obligations apply to the business
The first step toward compliance with the 2025 Cybersecurity Law is not deploying technology. It is accurately identifying the systems, platforms, and activities operated by the business that may fall within the law’s scope.
The business should establish a review team comprising representatives from senior management, legal, information technology, information security, data governance, and critical business functions. At a minimum, the team should answer the following questions:
What information systems does the business currently operate?
Which systems have a direct impact on business operations?
Does the business provide Internet-based services or digital platforms?
What types of data are being collected, stored, and shared?
Is the data stored in Vietnam, overseas, or across multiple cloud environments?
Which internal or external parties have access to the systems and data?
Are any foreign service providers or third parties involved in processing the data?
Does the business operate in an industry subject to additional sector-specific requirements?
The output of this step should be a documented compliance scope, rather than a general assumption that “all company systems are in scope.”
Businesses should also avoid combining the Cybersecurity Law with every obligation relating to data into a single undifferentiated requirement. A system may simultaneously be subject to the Cybersecurity Law, the Data Law, personal data protection regulations, and sector-specific rules. Businesses should therefore develop a consolidated obligations matrix while clearly identifying the legal basis for each requirement.
2. Inventory systems, data and service providers
A business cannot protect or demonstrate control over assets that it has not fully identified.
To prepare for compliance with the 2025 Cybersecurity Law, businesses should create and maintain an inventory covering at least:
Physical and virtual servers.
Cloud systems, SaaS platforms, and outsourced applications.
Websites, mobile applications, APIs, and customer portals.
Network devices, firewalls, VPNs, and remote-access equipment.
Computers, mobile devices, and user accounts.
Databases and storage repositories.
Email, identity, and authentication systems.
Software developed internally by the business.
Service providers authorized to access systems or data.
Each asset should have an identified owner, purpose, criticality rating, data classification, storage location, and responsible operating party.
For data, the business should develop data-flow diagrams identifying where data is collected, which systems it passes through, how long it is retained, with whom it is shared, and how it is deleted.
The inventory should not be treated as a one-time exercise. It must be updated whenever the business introduces a new application, migrates to the cloud, integrates an API, changes service providers, or deploys an AI tool.
3. Establish cybersecurity responsibilities and governance mechanisms
Compliance cannot be treated solely as the responsibility of the IT department. IT may operate the technology, but it cannot independently determine all legal requirements, risk-acceptance levels, or responses to incidents affecting customers.

Businesses should clearly define the following responsibilities.
Senior management
Approve policies and risk-acceptance levels.
Allocate appropriate resources.
Monitor significant risks.
Decide how to address deficiencies that cannot be remediated immediately.
Legal or compliance department
Identify applicable legal obligations.
Monitor changes in laws and regulations.
Review contracts with service providers.
Advise on obligations to cooperate, notify relevant parties, or provide information when an event occurs.
IT and Information security teams
Implement technical controls.
Monitor vulnerabilities, configurations, and logs.
Detect, investigate, and respond to incidents.
Maintain technical evidence.
Business departments
Identify critical data and business processes.
Comply with system access and acceptable-use policies.
Participate in risk assessments.
Report unusual or suspicious events.
At a minimum, the business should issue an overarching cybersecurity policy and supporting procedures for account management, vulnerability management, backups, incident response, service-provider management, and change management.
4. Implement technical measures based on risk
Laws and policies are meaningful only when translated into protective measures that can be tested and verified.
Access control
Businesses must ensure that users receive only the access rights required for their work. Administrative accounts, shared accounts, and service-provider accounts should be subject to stricter controls than ordinary user accounts.
Priority measures should include:
Applying multi-factor authentication to critical accounts.
Separating administrative accounts from accounts used for everyday work.
Reviewing access rights periodically.
Revoking accounts immediately when employees leave or change roles.
Monitoring unusual login activity.
Restricting the use of shared accounts.
Vulnerability and configuration management
Businesses should have a process for discovering, assessing, and remediating vulnerabilities according to risk. Running a scanning tool without tracking remediation does not create meaningful compliance value.
The process should define:
Which systems are scanned.
How frequently assessments are performed.
How severity is classified.
The applicable remediation deadlines.
The person responsible for remediation.
The circumstances in which retesting is required.
For websites, applications, APIs, cloud environments, or critical systems, businesses may conduct penetration testing to determine whether identified weaknesses can be exploited under realistic conditions.
Penetration testing is only one component of a security program. It does not replace governance, monitoring, training, backups, or incident response.
Data protection
Businesses should determine which data must be encrypted while stored or transmitted, who is authorized to decrypt it, and how encryption keys are managed.
Measures to consider include:
Encrypting critical data.
Applying role-based access controls.
Restricting data downloads to personal devices.
Controlling the external sharing of data.
Maintaining backups separate from the primary system.
Testing data-restoration capabilities.
Recording access to and modification of data.
Businesses should not assume that using cloud services transfers all responsibility to the cloud provider. The business remains responsible for managing accounts, configurations, access rights, data, and contractual obligations within its area of control.
Logging and monitoring
Businesses should determine which events must be logged, where logs are stored, who may access them, and how alerts are generated for suspicious activity.
Logging should cover critical systems and events such as:
Login and authentication activity.
Administrative-account activity.
Configuration changes.
Database access.
Endpoint security events.
Firewall, VPN, and cloud activity.
Actions performed through privileged service-provider accounts.
Maintaining logs without monitoring them, or being unable to retrieve them during an incident, significantly reduces the organization’s ability to investigate events and demonstrate that controls have been operating.
5. Establish a cybersecurity incident response process
Compliance with the 2025 Cybersecurity Law requires businesses to prepare in advance for detecting, receiving, classifying, and responding to incidents. Responsibilities should not be assigned only after an attack has already occurred.
The incident response plan should clearly answer the following questions:
Who is the primary point of contact for receiving alerts?
Which criteria are used to classify an incident?
Who has the authority to isolate a server or suspend an account?
When should the crisis management team be activated?
Who is responsible for collecting and preserving evidence?
At what stage should the legal department become involved?
Who communicates with customers, partners, and competent authorities?
In what order should systems be restored?
Who is responsible for conducting the post-incident root-cause assessment and tracking remediation?
Businesses should maintain emergency contact lists, escalation diagrams, and response playbooks for ransomware, data breaches, account compromise, website attacks, lost devices, and service-provider incidents.
The plan must be tested through exercises. A procedure that has never been tested may fail during an actual incident.
6. Control service-provider and supply-chain risks
Many businesses maintain relatively secure internal systems but remain exposed through IT partners, software developers, cloud providers, or remote-support accounts.
To comply effectively with the 2025 Cybersecurity Law, businesses should integrate security requirements throughout the entire service-provider lifecycle.
Before signing a contract, the business should assess:
Which systems or data the provider will access.
Where the data will be stored.
Whether subcontractors will be used.
Whether the provider adequately controls privileged accounts.
Whether backup and restoration mechanisms are available.
Whether logs can be provided during an incident.
Whether the provider has an incident-notification process.
Contracts should clearly define:
The permitted scope of data processing.
Minimum security requirements.
Incident-notification timeframes.
Responsibilities for supporting investigations.
Audit rights or rights to request evidence.
Conditions governing the use of subcontractors.
Procedures for returning or deleting data.
Methods for revoking accounts when the contract ends.
The IT department should not independently approve all service-provider risks. Arrangements involving critical data should also be reviewed by legal, information security, and the relevant business process owner.
7. Train employees and verify implementation
Employees directly use email, data, accounts, and systems. Compliance therefore cannot be demonstrated solely through signed policy acknowledgements.
The training program should be tailored to different roles:
General employees: phishing, passwords, data handling, and event reporting.
Managers: access approvals, risk management, and incident handling.
IT personnel: configuration, patching, logging, backups, and administrative accounts.
Developers: secure software development and source-code management.
Human resources personnel: employee account lifecycle management.
Legal personnel: legal obligations and incident coordination.
Senior management: governance responsibilities and decision-making.
Businesses may refer to IPSIP’s cybersecurity training and consulting services when developing content appropriate for different employee groups and internal policies.
After training, the business should assess employee understanding and behavioral changes through tests, phishing simulations, incident-response exercises, or evaluations of policy implementation.
8. Maintain evidence of compliance
A common gap is that a business may have implemented certain security measures but cannot provide records showing who performed them, when they were performed, and what the results were.
The compliance documentation set should include:
Control Area | Records or Evidence to Maintain |
Governance | Policies, responsibility-assignment decisions, approval records |
Assets | System inventories, network diagrams, application inventories |
Data | Data-flow diagrams, data inventories, access permissions |
Accounts | Access lists, review records, account-revocation records |
Vulnerabilities | Scan reports, penetration-test reports, remediation plans, retest results |
Incidents | Incident response plans, incident logs, exercise reports |
Backups | Backup policies, backup logs, restoration-test results |
Service Providers | Assessment forms, contracts, SLAs, control evidence |
Training | Training materials, attendance lists, test results |
Monitoring | Logs, alerts, remediation tickets, and periodic reports |
Records must reflect actual operations. Drafting policies without operational evidence may create the appearance of compliance on paper but does not meaningfully reduce risk.
9. Conduct a gap assessment and develop a remediation plan
After determining the applicable scope, the business should compare the applicable requirements with its current controls.
The gap assessment should be conducted across three layers:
Legal layer: Has the business fully identified its applicable obligations?
Governance layer: Are the necessary policies, responsibilities, and procedures in place?
Technical layer: Are the controls configured and operating effectively?
Each deficiency should be recorded together with:
The affected system or process.
The related obligation.
The business risk.
The priority level.
The responsible person.
The completion deadline.
The evidence required to close the item.
Businesses do not necessarily need to address every issue simultaneously. Priority should be given to deficiencies that could result in loss of account control, data exposure, disruption to critical systems, or an inability to detect and respond to incidents.
Small and medium-sized businesses without a dedicated security team can begin with a business cybersecurity assessment to identify priority gaps before investing in additional technology.
2025 Cybersecurity Law Compliance Checklist for Businesses
Businesses can use the following checklist to conduct an initial readiness review:
Applicable laws, regulations, and obligations have been identified.
A compliance team has been established.
Systems, applications, data, and service providers have been inventoried.
An accountable owner has been assigned to each critical system.
A cybersecurity policy has been issued.
Account and access-right management controls have been implemented.
Multi-factor authentication is enabled for critical accounts.
Vulnerability and patch-management procedures are in place.
Critical systems undergo periodic security assessments.
Backup and restoration-testing mechanisms have been implemented.
Logging is enabled on critical systems.
A person or service provider is responsible for monitoring alerts.
An incident response plan has been developed and tested.
Service-provider contracts contain security provisions.
Employees have received role-based training.
A remediation plan has been established and tracked through completion.
Compliance documentation is centrally managed and periodically updated.
This checklist provides only an initial indication of readiness. Every “Yes” answer should be supported by corresponding documentation, configurations, logs, or operational evidence.
5 common misconceptions about 2025 Cybersecurity Law Compliance
1. Having ISO 27001 certification means the business is already compliant
ISO 27001 can provide a foundation for information security management, but the business must still map its controls against each applicable legal obligation.
2. Penetration testing eliminates the need for a compliance assessment
Penetration testing focuses on whether technical weaknesses can be exploited. A compliance assessment also covers governance, procedures, data, service providers, training, and supporting evidence.
3. A Firewall and antivirus software are sufficient
These tools do not replace account management, log monitoring, data protection, incident response, or third-party risk controls.
4. Using cloud services makes the provider fully responsible
Cloud services generally operate under a shared-responsibility model. The business remains responsible for controlling accounts, configurations, data, and how the service is used.
5. Compliance can be maintained after completing a one-time project
Systems, data, personnel, service providers, and threats continually change. Businesses must conduct periodic assessments and additional reviews following significant changes.
Compliance with the 2025 Cybersecurity Law is not achieved by purchasing a product or completing a set of documents. It is a continuous process involving scope identification, asset management, data protection, access control, monitoring, incident response, service-provider management, and the maintenance of evidence.
Businesses should begin with a gap assessment to determine what is missing from their current environment, which risks should be prioritized, and which measures genuinely require investment. This approach helps prevent businesses from purchasing numerous tools while remaining unable to demonstrate compliance or effective system protection.
IPSIP can help businesses review their current environments, assess governance and technical gaps, determine remediation priorities, and develop an improvement roadmap appropriate for their scale of operations. Businesses can schedule a consultation with IPSIP to determine the scope of an initial assessment.
-------------
References
Law No. 116/2025/QH15 of the National Assembly: Cybersecurity Law: https://vanban.chinhphu.vn/?classid=1&docid=216499&orggroupid=1&pageid=27160
National Database of Legal Documents: https://vbpl.moj.gov.vn/TW/Pages/vbpq-toanvan.aspx?ItemID=187039
Decree No. 53/2022/ND-CP detailing a number of articles of the Cybersecurity Law: https://vanban.chinhphu.vn/?docid=206381&pageid=27160










Comments