top of page

Cybersecurity Law Report: A detailed guide for IT leaders (CIO/CISO) in 2026

8 hours ago
3 min read

The 2025 Cybersecurity Law (No. 116/2025/QH15) officially took effect on July 1, 2026. We are currently in a critical 12-month transition period (lasting until July 1, 2027) for organizations and enterprises to review, upgrade their systems, and achieve full compliance with the new standards.

To help organizations stay informed, the Department of Cyber Security and High-Tech Crime Prevention (Ministry of Public Security) has released the "Cybersecurity Law Handbook." This article by IPSIP Vietnam highlights the core updates from the report, helping IT leaders, CIOs, and CISOs build effective security strategies and ensure regulatory compliance.

1. Context and significance of the 2025 Cybersecurity Law

Passed by the 15th National Assembly on December 10, 2025, the 2025 Cybersecurity Law was enacted to safeguard national sovereignty, security, and data in the digital transformation era.

cybersecurity-law-report
Cybersecurity Law Report

Notably, this law replaces and merges the 2015 Law on Cyber Information Security and the 2018 Cybersecurity Law. Consolidating state management into a single authority eliminates legislative overlaps, creating a unified legal framework that strengthens cybersecurity while driving digital economic growth.

2. 5 core changes enterprises must keep in mind

According to the handbook from the Ministry of Public Security, here are five critical changes and new regulations that all enterprises operating in Vietnam, especially telecom, internet, and digital platform service providers must understand:

2.1. Independent definition of data protection for the first time

Data is now officially recognized as a strategic resource. The law clearly mandates control over the entire data lifecycle. Unauthorized collection, trading, exchange, or use of personal information and digital identities is strictly prohibited.

2.2. Strict penalties for misuse of AI & Deepfake technology

Amid the explosive rise of Artificial Intelligence, the 2025 Law strictly prohibits abusing AI and Deepfakes to forge images, video, or voice for fraud, defamation, or extortion. Service providers are required to deploy technical measures to scan, identify, and block malicious content.

2.3. Five-tier system classification for information systems

The new law classifies information systems into five levels based on their potential impact on national security and public order:

  • Levels 1-2: Enterprises may autonomously select protection measures.

  • Levels 3-4: Mandatory compliance with baseline security requirements as defined by law.

  • Levels 5: Stringent protection of critical national security systems through mandatory evaluation, certification, continuous monitoring, and periodic audits.

2.4. Incident response & Content removal obligations (24h - 6h SLA)

Service providers must establish rapid incident response mechanisms:

  • Blocking and removing violating content: Within 24 hours of receiving an official request.

  • Emergency situations (impacting national security): Must be processed within 6 hours max.

    Additionally, enterprises are required to track traces, locate IPs, and provide technical information to assist law enforcement investigations upon request.

2.5. Mandatory allocation of at least 15% budget for cybersecurity

This is a game-changing regulation for IT budgeting. For digital transformation initiatives and IT projects, organizations must allocate a minimum of 15% of the total budget specifically for cybersecurity protection. This measure also encourages prioritizing qualified "Make in Vietnam" products that meet technical standards.

3. Transitional provisions: The countdown has begun

Enterprises have no time to delay. Under the transitional provisions:

  • Systems previously assigned security levels retain their classifications, but must update and comply with new cybersecurity standards and protection measures within 12 months from the effective date (July 1, 2026).

  • Previously issued cyber information security licenses will remain valid until their expiration date.

[EXCLUSIVE RESOURCE] Download the complete Cybersecurity Law Handbook 2025

Misunderstanding or delaying compliance with the Cybersecurity Law can result in massive legal risks, service suspension, or severe reputational damage.

To equip your Legal and IT teams with accurate insights, download the full "Cybersecurity Law Handbook 2025" report (Original document from the Department of Cyber Security and High-Tech Crime Prevention - Ministry of Public Security).



Future-proof your infrastructure with IPSIP

Strict 5-tier classification rules, stringent incident response SLAs (24h/6h), and mandatory 15% IT budget allocations require organizations to maintain an agile, comprehensive cyber defense infrastructure supported by round-the-clock security experts.

Delivering world-class cybersecurity services, IPSIP Vietnam is proud to be your strategic partner in ensuring full compliance with the 2025 Cybersecurity Law:

  • Security assessment & Pentest: Penetration testing, system level determination, and vulnerability identification before malicious actors exploit them.

  • 24/7 SOC Services (Security Operations Center): Real-time monitoring, threat detection, and incident response meeting regulatory SLA standards.

  • Managed IT & Cloud security consulting: Infrastructure optimization and data protection at optimal costs, ensuring IT budgets are legally compliant and effectively allocated.

ipsip-viet-nam
IPSIP Vietnam provides optimal cybersecurity solutions that ensure full regulatory compliance for enterprises

Don't let legal risks impede your business growth. Partner with IPSIP's experts to build a robust cyber defense shield today!

Contact IPSIP now for an assessment and a tailored IT roadmap to meet the 2025 Cybersecurity Law standards.

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page