Vietnam’s latest Cybersecurity Law 2026: What businesses need to know
- Hung Pham

- Jul 1
- 7 min read
Vietnam’s latest Cybersecurity Law in 2026 is Law No. 116/2025/QH15, passed by the National Assembly on December 10, 2025, and effective from July 1, 2026. Therefore, when reviewing applicable regulations after this date, businesses should not rely solely on Cybersecurity Law No. 24/2018/QH14 or advisory materials published before July 2026.
This change is particularly important for digital service providers, telecommunications and Internet companies, online platforms, cloud computing providers, businesses operating important information systems, and organizations processing large volumes of data in Vietnam.
However, complying with the Cybersecurity Law does not simply mean updating the name of a new legal document. Businesses need to review the Cybersecurity Law together with the Data Law, the Personal Data Protection Law, and relevant implementing decrees to correctly determine their obligations regarding systems, data, and service operations.
Note: The content below provides general information on cybersecurity compliance and does not replace legal advice for a specific case.
What is Vietnam’s latest Cybersecurity Law in 2026?
As of July 23, 2026, the latest law directly regulating cybersecurity is Cybersecurity Law No. 116/2025/QH15.

The law was issued on December 10, 2025, and officially took effect on July 1, 2026. This is the date businesses need to remember when reviewing policies, contracts, operating procedures, and internal compliance documents.
Before July 1, 2026, Cybersecurity Law No. 24/2018/QH14, effective from January 1, 2019, served as the foundational law. Decree No. 53/2022/ND-CP was issued to provide detailed guidance on several provisions of that law and took effect on October 1, 2022.
Therefore, when reading an article stating that “the 2018 Cybersecurity Law is still the latest law,” businesses must check the publication or update date. That conclusion was only accurate before July 1, 2026.
To follow the specific changes and learn how to build a defense system under the new legal context, businesses can refer to the analysis of the latest Cybersecurity Law and the “dual shield” model in 2026.
Legal documents businesses need to monitor in 2026
The Cybersecurity Law does not operate independently. In practice, a data processing activity or digital system may simultaneously be subject to several groups of regulations.
Legal document | Effective date | Scope businesses need to consider |
Cybersecurity Law No. 116/2025/QH15 | July 1, 2026 | Protection of national security, public order, and lawful rights and interests in cyberspace; responsibilities of agencies, organizations, and businesses |
Data Law No. 60/2024/QH15 | July 1, 2025 | Data governance, development, processing, and use |
Personal Data Protection Law No. 91/2025/QH15 | January 1, 2026 | Rights of data subjects and responsibilities of personal data controllers and processors |
Decree No. 356/2025/ND-CP | January 1, 2026 | Detailed regulations and implementation measures for the Personal Data Protection Law |
Decree No. 53/2022/ND-CP | October 1, 2022 | Guidance for the 2018 Cybersecurity Law, which must be reviewed together with transitional provisions and new legal documents |
Data Law No. 60/2024/QH15 was issued on November 30, 2024, and took effect on July 1, 2025. Personal Data Protection Law No. 91/2025/QH15 took effect on January 1, 2026; on the same date, Decree No. 356/2025/ND-CP also became effective to provide detailed implementation guidance.
This means that a business collecting customer information through a website does not only need to consider server security. It must also review the purpose of collection, legal basis for processing, access rights, retention periods, third-party recipients, data transfer flows, and the response process when an incident occurs.
For in-depth information on infrastructure and data location, see the 2026 cybersecurity regulations on data storage in Vietnam.
Which businesses are subject to the 2026 Cybersecurity Law?
In principle, organizations and businesses operating in cyberspace in Vietnam need to assess how the Cybersecurity Law applies to their activities. However, the scope and level of obligations are not the same for every business.
Groups that should prioritize compliance reviews include:
Telecommunications, Internet, and cyberspace service providers.
Digital platforms collecting or processing data of users in Vietnam.
Cloud, data center, or software-as-a-service providers.
Banks, financial institutions, insurers, healthcare providers, energy companies, and industries handling sensitive data.
Organizations operating information systems important to national security.
Foreign businesses providing services or processing data related to users in Vietnam.
Businesses with cross-border data flows or allowing foreign partners to access data.
FDI enterprises should not assume that having a parent company or servers located overseas automatically places them outside the scope of the law. Obligations must be determined based on actual operations in Vietnam, the type of services provided, the categories of data processed, and the relationship with domestic users.
This topic is analyzed separately in the guide to the Cybersecurity Law for FDI enterprises: challenges and solutions in 2026.
What obligations must businesses fulfill?
The Cybersecurity Law has a broad scope, but for most businesses, its requirements can be translated into five practical areas of work.

1. Identify the systems and data under management
Businesses need to create an inventory of:
Information systems currently in operation.
Databases and storage locations.
Types of data being collected.
Owners and responsible units.
Cloud providers, software vendors, and outsourced processors.
Data flows between Vietnam and other countries.
Without a system and data map, businesses will find it difficult to determine which regulations apply or where risks currently exist.
2. Implement information system protection Measures
Businesses need to implement security measures appropriate to the level of risk, rather than simply installing antivirus software and considering compliance complete.
Controls that typically need to be reviewed include:
Account and access management.
Multi-factor authentication.
Patch and vulnerability management.
Endpoint protection.
Network segmentation.
Data backup and recovery.
Appropriate data encryption.
Logging and event monitoring.
Vendor management.
Incident response planning.
Businesses can use the cybersecurity safety assessment service to identify gaps between legal requirements, internal policies, and the actual technical environment.
3. Establish incident detection and response mechanisms
Compliance is not assessed only by the ability to prevent attacks. Businesses must also demonstrate that they can detect, isolate, investigate, recover from, and report incidents in accordance with applicable regulations.
A response plan should clearly define:
Which events are considered incidents.
Who has the authority to activate emergency procedures.
Which unit is responsible for technical response.
When the legal and communications teams become involved.
How logs and evidence are preserved.
The conditions for notifying authorities or affected data subjects.
How operations are restored without destroying evidence.
For businesses without continuous monitoring teams, implementing a 24/7 Security Operations Center service can support early detection and standardize incident response procedures.
4. Govern personal data and cross-border data
From 2026, cybersecurity governance must be closely connected with personal data governance. Businesses need to understand whether they act as data controllers, data processors, or simultaneously perform multiple roles.
Areas that need to be reviewed include:
The purpose and scope of data collection.
Employee access rights.
Data sharing with service providers.
Data retention and deletion periods.
Overseas data transfers.
Records and documentation demonstrating compliance.
Mechanisms for receiving requests from data subjects.
Procedures for handling data breaches.
Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP both took effect on January 1, 2026, so procedures developed only under Decree No. 13/2023 need to be reassessed.
Businesses can also refer to the guide to enforcing personal data protection law in 2026.
5. Cooperate with competent authorities when legally required
Some businesses providing services in cyberspace may be required to provide information, cooperate in verification, prevent violations, or handle unlawful content and activities upon receiving lawful requests from competent authorities.
Businesses need to standardize request-handling procedures to avoid two opposing risks:
Delaying or failing to fulfill legal obligations.
Providing data beyond the necessary scope or without proper authority.
Every request should be recorded, the requesting authority should be verified, the legal basis should be assessed, internal approval should be obtained, and evidence of the handling process should be retained.
What are the consequences of failing to comply with the Cybersecurity Law?
There is no single penalty that applies to every act described as a “violation of the Cybersecurity Law.” The form of enforcement depends on the specific conduct, the severity of the consequences, the type of data, the type of system, and the specialized sanctioning regulations applied.
Depending on the case, an organization or individual may face:
Administrative penalties.
Orders to remedy or terminate the violation.
Orders to remove, block, or handle unlawful information.
Suspension of part of an operation or service under applicable legal grounds.
Liability for damages.
Disciplinary or criminal liability if the conduct meets the required legal elements.
Loss of reputation among customers and partners.
Operational disruption because systems are isolated or investigated.
Therefore, businesses should not include a single general penalty figure in internal policies. A safer approach is to build a matrix of obligations, violations, applicable legal documents, and responsible units.
Cybersecurity Law Compliance checklist for businesses in 2026
Businesses can begin with the following 10 questions:
Has Cybersecurity Law No. 116/2025/QH15 been added to the compliance register?
Have the systems that require special protection been identified?
Has a data map and cross-border data flow map been created?
Have personal data protection policies been reviewed under the law effective from January 1, 2026?
Has an owner been assigned to each system and database?
Have vulnerability assessments or security penetration tests been conducted periodically?
Are centralized logs and anomaly detection mechanisms in place?
Has the incident response plan been tested?
Have the obligations of cloud, SaaS, and outsourced service providers been assessed?
Are records demonstrating the compliance process being retained?
This checklist does not replace legal and technical assessments tailored to a specific industry. However, if a business cannot answer three or more questions, this is a sign that a structured review should be conducted.
Vietnam’s latest Cybersecurity Law in 2026 is Law No. 116/2025/QH15, effective from July 1, 2026. The most important issue for businesses is not only acknowledging the new law, but also conducting a coordinated review of information systems, data, vendors, cross-border data flows, and incident response capabilities.
Businesses should proceed in the following order: determine the scope of application, map systems and data, assess compliance gaps, remediate priority risks, and maintain supporting compliance records. Issues relating to data storage, personal data, FDI enterprises, cloud services, and important systems need to be assessed separately according to the actual operating model.
To identify gaps between legal requirements and the current security environment, businesses can schedule a consultation with IPSIP Vietnam or refer to the cybersecurity training and consulting service.
----------------
Referral
Luật An ninh mạng số 116/2025/QH15: Cổng Thông tin điện tử Chính phủ.
Luật An ninh mạng số 24/2018/QH14: Cổng Thông tin điện tử Chính phủ.
Nghị định số 53/2022/NĐ-CP: Cổng Thông tin điện tử Chính phủ.
Luật Dữ liệu số 60/2024/QH15: Cổng Thông tin điện tử Chính phủ.
Luật Bảo vệ dữ liệu cá nhân số 91/2025/QH15: Cổng Thông tin điện tử Chính phủ.
Nghị định số 356/2025/NĐ-CP: Cổng Thông tin điện tử Chính phủ.










Comments