top of page

Mandatory information security assessment organization: Vendor selection criteria

Businesses should assess providers across three layers: identify the exact compliance obligation, verify the provider's licenses and legal eligibility, and then evaluate its technical capabilities against the actual system scope.

A provider with a strong brand or a large team of penetration testers may not be suitable for every type of assessment. Likewise, holding an appropriate license does not automatically mean the provider has sufficient experience with the technologies, data, and architecture used by a particular business.

A sound selection process should therefore answer at least the following questions:

  • What requirement is driving the assessment?

  • What type of service is actually required?

  • Is the provider legally permitted to deliver that service?

  • Who will perform the work?

  • Which assets are included in scope?

  • Is the methodology appropriate for the system?

  • How will data and technical evidence be protected?

  • Will the final report be actionable for remediation?

  • Is retesting included after remediation?

mandatory-information-security-assessment-organization
Mandatory information security assessment organization

1.What does “mandatory information security assessment organization” mean in Vietnam in 2026?

The phrase “mandatory information security assessment organization” is commonly used by businesses searching for a third party to inspect or assess systems in connection with legal or compliance obligations.

However, businesses should not automatically treat this phrase as the formal legal name of a specific type of organization applicable in every case.

Under Decree No. 332/2026/ND-CP, one directly relevant legal concept is “cybersecurity inspection and assessment services.” These services include scanning, inspection, analysis of configurations, system status and system logs, identification of vulnerabilities and weaknesses, and assessment of cybersecurity risks.

👉 Businesses can refer to the full text of Decree No. 332/2026/ND-CP.

This distinction matters when preparing an RFP or requesting quotations. A business should determine whether it actually needs:

  • cybersecurity inspection and assessment;

  • cybersecurity risk assessment;

  • penetration testing;

  • vulnerability scanning;

  • compliance auditing;

  • configuration assessment;

  • cybersecurity consulting;

or a combination of several services.

The commercial name of a service package does not determine its legal nature. The scope of work and applicable legal basis are what should be examined.

Businesses that want to understand the technical scope commonly covered by an information security inspection and assessment service can begin with areas such as networks, servers, applications, APIs, cloud environments, privileged accounts, endpoints, security configurations, and monitoring systems.
  1. Periodic information security assessments: Does every business follow the same schedule?

A periodic information security assessment should not be understood as a single fixed cycle that applies identically to every company and every information system.

Under Clause 2, Article 10 of Decree No. 331/2026/ND-CP, information system owners must conduct a cybersecurity risk assessment in five circumstances:

  1. When determining the information system security level for the first time.

  2. When changing the system's functions, service scope, user groups, types of information processed, or deployed technologies.

  3. When expanding the system, integrating it with other systems, establishing interconnections, or sharing data.

  4. When a serious cybersecurity incident occurs or when there is a high risk affecting national security, public order and safety, or public interests.

  5. When requested by a competent state authority.

👉 Businesses can review the explanation at LuatVietnam – Five cases requiring cybersecurity risk assessment.

Risk assessment results may also provide a basis for proposing, determining, or adjusting the security level of an information system, selecting appropriate cybersecurity safeguards, and developing suitable protection plans.

How should “periodic assessment” be interpreted?

From a governance perspective, businesses should still establish recurring assessment cycles based on risk. However, they should avoid presenting a single frequency as a universal legal obligation unless there is a specific legal basis for doing so.

The actual frequency should take into account:

  • the information system's security level and criticality;

  • the type of data processed;

  • changes in architecture or technology;

  • cloud environments and third-party connections;

  • vulnerability exposure;

  • incident history;

  • sector-specific regulations;

  • requirements from competent authorities;

  • contractual obligations to customers or parent companies;

  • standards or frameworks adopted by the organization.

In short, periodic assessment is an important part of risk management, but the assessment cycle should be determined based on applicable obligations and actual risk conditions.
  1. 7 criteria for choosing a mandatory information security assessment organization

A suitable provider should pass two separate tests: legal eligibility and technical capability.

The table below can be used as an initial screening framework when preparing an RFP, requesting quotations, or evaluating service providers.

Criterion

What the business should verify

Evidence to request

1. Legal status and licensing

Is the provider permitted to deliver the specific service required?

License, permitted service scope, validity period

2. Technical personnel

Who will perform the assessment, and are they qualified for the environment?

Key personnel list, qualifications/certifications, roles

3. Assessment scope

Does the scope cover the relevant assets and critical risks?

Scope of Work, asset inventory, exclusions

4. Assessment methodology

Does the provider perform manual validation or only automated scanning?

Methodology, risk classification criteria

5. Data protection

How are credentials, logs, and technical evidence stored and processed?

NDA, retention procedures, access controls, destruction procedures

6. Reporting quality

Is the report useful for both IT teams and management?

Sanitized sample report

7. Post-assessment support

Does the provider explain findings and conduct retesting?

Retest policy, handover workshop, remediation support scope

3.1 Verify legal eligibility before reviewing certifications

Decree No. 332/2026/ND-CP establishes conditions for organizations and enterprises engaged in the business of cybersecurity products and services.

General conditions include being legally established under Vietnamese law, having appropriate personnel responsible for technical activities, and maintaining equipment, facilities, and technologies suitable for the registered business activities.

For certain services, the requirements are more specific.

Under Article 8 of Decree No. 332/2026/ND-CP, providers of cybersecurity inspection services and cybersecurity consulting services must have a technical team of at least five people with university-level qualifications or cybersecurity certificates or higher, with specific residential addresses in Vietnam. The legal representative must be a Vietnamese national.

Providers must also maintain appropriate technical plans, contingency plans, business plans, customer information protection measures, and service quality assurance measures.

Therefore, a company profile filled with international certifications or penetration-testing projects does not replace verification of legal eligibility when the purchased service falls within a regulated business category.

3.2 Technical capabilities must match the actual system

Legal eligibility should be followed by technical assessment.

A provider that is highly experienced in web application testing may not have the same depth in OT/ICS environments. Similarly, a cloud security specialist may not be the right person to assess Active Directory or a complex enterprise network.

Businesses should ask providers to explain how the assessment scope is built from the actual asset inventory rather than offering the same checklist to every customer.

The inventory may include:

  • websites and web applications;

  • mobile applications;

  • APIs;

  • servers;

  • databases;

  • Active Directory;

  • cloud workloads;

  • firewalls, routers, and switches;

  • endpoints;

  • privileged accounts;

  • logging infrastructure;

  • VPNs;

  • third-party and partner connections.

A security vulnerability inspection and assessment is most useful when findings are analyzed in the context of assets, data, exploitability, and business impact.

3.3 The scope must be clearly defined before signing the contract

A quotation stating “full system assessment” without an asset list should be treated cautiously.

The scope should define at minimum:

  • which IP addresses or subnets will be tested;

  • which applications and APIs are included;

  • whether production or staging systems are involved;

  • which accounts will be provided;

  • which cloud accounts or environments are included;

  • what types of testing are permitted;

  • the permitted testing window;

  • prohibited actions;

  • systems or data specifically excluded from testing.

The clearer the scope, the easier it becomes to compare competing proposals on a like-for-like basis.

3.4 The methodology should go beyond automated scanning

A scanner is a supporting tool, not the entire assessment.

Businesses should ask the provider to explain how it will:

  • discover and validate assets;

  • review configurations;

  • analyze access rights;

  • identify vulnerabilities;

  • eliminate false positives;

  • perform manual verification;

  • evaluate exploitability;

  • identify potential attack paths;

  • assess impact;

  • classify risk levels;

  • recommend remediation measures.

If the provider simply promises to deliver a list of vulnerabilities generated by automated tools, the business value of the engagement may be limited.

3.5 Evaluate the actual project team, not only the corporate profile

Do not stop at the provider's company profile.

Businesses should know who will actually perform the work.

Useful questions include:

  • Who is the technical lead?

  • Who will perform the assessment?

  • What experience do they have with similar systems?

  • Will subcontractors be used?

  • Who reviews findings?

  • Who approves the final report?

  • Can assigned personnel change between the proposal and delivery stages?

Professional certifications are useful supporting evidence, but they should not be the only measure of capability.

3.6 There must be a mechanism for protecting data and technical evidence

During an assessment, a provider may gain access to highly sensitive information, including:

  • network diagrams;

  • IP addresses;

  • testing accounts;

  • credentials;

  • logs;

  • system configurations;

  • vulnerability information;

  • screenshots and technical evidence;

  • sample data;

  • cloud configurations.

Businesses should establish clearly:

  • how information is transmitted;

  • where it is stored;

  • whether it is encrypted;

  • who can access it;

  • how long it is retained;

  • how backups are handled;

  • how information is destroyed after the project.

An NDA is important, but an NDA cannot replace technical controls and proper data-handling procedures.

3.7 Reporting quality and retesting should be evaluated before purchase

A high-quality report should not merely list CVEs and CVSS scores.

Each significant finding should explain:

  • which asset is affected;

  • where the weakness exists;

  • what evidence supports the finding;

  • the conditions required for exploitation;

  • technical impact;

  • impact on data or business operations;

  • remediation priority;

  • recommended corrective action;

  • how remediation can be verified.

Businesses should request a sanitized sample report with all client-identifying information removed.

The contract should also clarify:

  • how many retest rounds are included;

  • the retest request period;

  • how findings are updated;

  • whether a handover workshop is included;

  • what the final post-retest report will contain.

A good assessment does not end when a vulnerability is found. The proper cycle is: Identify → Analyze → Remediate → Retest → Confirm risk reduction.
mandatory-information-security-assessment-organization
7 criteria for choosing a mandatory information security assessment organization
  1. Is an enterprise cybersecurity audit the same as penetration testing or system assessment?

No. An enterprise cybersecurity audit, system security assessment, vulnerability scan, and penetration test may overlap, but they should not be treated as interchangeable activities.

Activity

Primary focus

Typical output

Enterprise cybersecurity audit

Policies, processes, controls, evidence, and compliance requirements

Compliance gaps, level of conformity, recommendations

System security assessment services

Security posture of assets and architecture

Weaknesses, risks, configuration issues, recommendations

Vulnerability scanning

Identification of known weaknesses at scale

Vulnerability list

Penetration testing

Validation of exploitability within an authorized scope

Exploitation evidence, attack paths, impact

For example, a penetration test may demonstrate that a vulnerability can be exploited to bypass authentication or access restricted data.

However, that penetration test does not automatically prove that the organization has adequately assessed access-control policies, logging, operating procedures, system classification, or other compliance obligations.

Businesses that need to clarify the technical differences before defining the scope can review the difference between penetration testing and vulnerability scanning
  1. What should system security assessment services include?

A strong system security assessment service should not begin with the question, “How many tools will be used?”

It should begin with: “What assets and risks does the business have?”

The assessment scope can be structured into four layers.

Layer 1: Assets

This may include:

  • servers;

  • workstations;

  • network devices;

  • websites;

  • mobile applications;

  • APIs;

  • databases;

  • cloud workloads.

Layer 2: Identity and access

This may include:

  • Active Directory;

  • IAM;

  • privileged accounts;

  • service accounts;

  • MFA;

  • access provisioning and revocation.

Layer 3: Data and connectivity

The organization should identify:

  • where critical data is stored;

  • which systems can access that data;

  • which APIs exchange information;

  • third-party connections;

  • VPNs;

  • remote-access mechanisms;

  • Internet-facing connections.

Layer 4: Operational controls

This may include:

  • patch management;

  • logging;

  • monitoring;

  • backup;

  • incident response;

  • vulnerability management;

  • change management.

Building the scope this way helps avoid a common problem: performing an extremely detailed assessment of a small application while overlooking a privileged account, cloud workload, or network connection that creates a much greater risk.

6. 6-step process for choosing an assessment provider and avoiding the wrong service

Step 1: Identify the basis for the assessment

The business must know why the assessment is being performed.

The requirement may originate from:

  • the Cybersecurity Law;

  • implementing decrees;

  • sector-specific regulations;

  • requirements from state authorities;

  • customers;

  • a parent company;

  • contractual obligations;

  • internal standards or frameworks.

Without identifying the basis first, the organization can easily purchase the wrong service.

Step 2: Identify the systems and data within scope

Create as detailed an asset inventory as possible.

The organization should identify:

  • systems;

  • system owners;

  • data processed;

  • technologies;

  • environments;

  • connections;

  • uptime requirements;

  • testing restrictions.

Step 3: Verify the provider's legal status

Ask the provider to submit relevant licensing information and verify:

  • business name;

  • issuing authority;

  • permitted service category;

  • scope;

  • validity period;

  • current license status.

Businesses should not rely solely on certification logos displayed on a website or statements made by a sales team.

Step 4: Evaluate capability against the scope, not the brand

Ask the provider to describe:

  • personnel assigned to the project;

  • relevant experience;

  • methodology;

  • manual testing;

  • tools;

  • testing limitations;

  • production-protection measures;

  • data-handling procedures.

Step 5: Review a sample report before signing

A sample report can reveal a great deal about the maturity of the service.

A report containing only a list of vulnerabilities is usually not sufficient.

Businesses should look for:

  • evidence;

  • business impact;

  • technical impact;

  • attack scenarios;

  • remediation guidance;

  • prioritization;

  • retest status.

Step 6: Connect the assessment to a remediation plan

Before the engagement begins, define:

  • which teams will remediate findings;

  • remediation deadlines;

  • prioritization criteria;

  • responsible contacts;

  • the retest plan.

The value of an assessment is not determined by how many vulnerabilities are discovered, but by how effectively the most important risks are reduced.
  1. Warning signs that a business may be choosing the wrong assessment provider

Businesses should exercise caution when a provider:

  • cannot clearly explain the objective of the assessment;

  • treats assessment and penetration testing as the same thing;

  • cannot clearly explain licensing and service scope;

  • does not identify the personnel who will perform the work;

  • uses essentially the same scope for every customer;

  • relies almost entirely on scanners;

  • has no clear data-protection process;

  • cannot provide a sample report;

  • does not define retesting;

  • makes claims such as “100% secure” or “no further risk of attack.”

Cybersecurity is not a permanent state that can be certified at a single point in time.

After an assessment, the system may still change because of:

  • software updates;

  • new users;

  • new APIs;

  • cloud changes;

  • new applications;

  • new vendor connections;

  • newly disclosed vulnerabilities;

  • changes in attacker techniques

8.Quick checklist before signing an assessment contract

Before approving a provider, businesses can review these 10 questions:

  1. Is the legal or compliance basis for the assessment clear?

  2. Has the required service type been correctly identified?

  3. Is the provider's license appropriate?

  4. Does the scope contain a specific asset inventory?

  5. Do you know who will actually perform the work?

  6. Does the methodology include manual verification?

  7. Is there a defined process for protecting customer data?

  8. Have you reviewed a sample report?

  9. Is retesting included in the contract?

  10. Has responsibility for remediating findings been assigned?

👉 If several answers are still “no,” the business should refine the requirements before signing the contract.

ipsip-vietnam-cybersecurity-solutions
IPSIP Vietnam cybersecurity solutions

If your business has a small internal IT team but is unsure where security gaps may exist across its network infrastructure, contact IPSIP Vietnam to discuss an approach based on your business size, technology environment, and actual risk profile.

ipsip-viet-nam-offers-a-15%-discount-for-new-customers
IPSIP Vietnam offers a 15% discount for new customers

🎉To assist enterprises in optimizing risk management costs, IPSIP Vietnam is currently rolling out a special promotional program: Get an immediate 15% discount on the total contract value for all new clients signing up for Pentest services or other solution suites. Sign up for IPSIP Vietnam's Pentest services today to undergo structured testing, analysis, and comprehensive security vulnerability remediation support, maximizing the protection of your digital assets!

References

Cybersecurity Law No. 116/2025/QH15 – Vietnam National Legal Database: View the full text of Cybersecurity Law No. 116/2025/QH15

Decree No. 331/2026/ND-CP on cybersecurity protection for information systems – Government Electronic Information Portal: View Decree No. 331/2026/ND-CP

Decree No. 332/2026/ND-CP on the business of cybersecurity products and services – Government Electronic Information Portal: View Decree No. 332/2026/ND-CP

Conditions for conducting cybersecurity product and service businesses – Vietnam Government Electronic Newspaper: View cybersecurity service business requirements

Five cases requiring cybersecurity risk assessment for information systems – LuatVietnam: View the analysis on LuatVietnam

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page