Every Information System in Việt Nam Gets a Security Level: Nghị định 331/2026/NĐ-CP Replaces the 2016 Rules

Of the five cybersecurity decrees the Government issued on 19 August 2026, the one with the widest reach is the one that got the least press. Nghị định 333 brought phone-number account verification, Nghị định 330 brought the fine schedule, Nghị định 332 brought vendor licences. Nghị định 331/2026/NĐ-CP does something quieter: it tells every organisation that runs an information system in Việt Nam — a ministry, a hospital, a bank, an e-commerce site — which of five security levels that system belongs to, who has to sign off on that classification, and what protection each level demands. For the roughly ten years before it, that job was done by a decree written under a law that no longer exists.

What the document is

Nghị định 331/2026/NĐ-CP “về bảo vệ an ninh mạng đối với hệ thống thông tin” was issued by the Government on 19 August 2026, signed by Standing Deputy Prime Minister Phạm Gia Túc, and took effect the same day (Điều 38). It runs to 6 chapters and 40 articles, followed by eight forms (Mẫu số 01 to 08). It details khoản 2 Điều 8, khoản 5 Điều 9, khoản 6 Điều 10 and khoản 5 Điều 12 of Luật An ninh mạng số 116/2025/QH15 — the articles on classifying information systems by level, on systems important to national security, on protective measures, and on cybersecurity inspection of systems outside the national-security list. That law, passed on 10 December 2025 and in force since 1 July 2026, merged the 2015 Luật An toàn thông tin mạng and the 2018 Luật An ninh mạng into one statute.

The decree replaces Nghị định 85/2016/NĐ-CP of 1 July 2016 on “bảo đảm an toàn hệ thống thông tin theo cấp độ”, the decree that introduced level-based security under the 2015 law. Between 1 July and 19 August 2026 the old decree was, formally, an orphan; this closes the gap.

The five levels, and where the lines moved

Both the old and new regimes use five levels, defined by how much harm a compromise would cause — from Level 1, which could harm the legitimate rights and interests of organisations and individuals, to Level 5, which could cause especially serious harm to national security. The criteria in the new decree, as summarised by Báo Chính phủ, LuatVietnam and Ban Cơ yếu Chính phủ, are:

  • Level 1 — systems serving only internal operations and processing only public information.
  • Level 2 — systems processing private or personal data (but not state secrets), and online services holding personal data on fewer than 100,000 data subjects for basic personal data or fewer than 10,000 for sensitive personal data.
  • Level 3 — systems processing state secrets or serving defence and security; online services at or above the 100,000 / 10,000 thresholds; services in conditional business lines; systems handling administrative procedures; shared infrastructure serving several organisations; and industrial control systems for works of Class II to IV.
  • Level 4 — state-secret or defence-security systems whose compromise would seriously harm national security; national e-government systems or nationwide infrastructure that must run 24/7 with no unplanned downtime; industrial control systems for Class I works.
  • Level 5 — strategic state-secret or defence-security systems whose compromise would cause especially serious harm; national data repositories; international connectivity infrastructure; control systems for special-class works. These are the “hệ thống thông tin quan trọng về an ninh quốc gia”.

The most consequential change for the private sector is the threshold. Under Nghị định 85/2016, an online service crossed from Level 2 to Level 3 at 10,000 users. The new decree raises that to 100,000 data subjects for basic personal data and, for the first time, sets a separate 10,000-subject line for sensitive data — the vocabulary is that of the Luật Bảo vệ dữ liệu cá nhân, not the old information-security law. A mid-sized app with 50,000 registered users that was a Level 3 system under the old rules may be Level 2 today; a health or fintech service with 15,000 users holding sensitive data is Level 3 regardless.

Three structural rules from LuatVietnam’s comparison table matter as much as the thresholds. A system that meets criteria from several levels takes the highest one, a principle the old decree applied only to systems with sub-components at different levels. System boundaries must be drawn by business function, data flow and operational dependency, and the decree explicitly forbids defining the scope of a system “một cách hình thức” to land it in a lower level. And when IT operations are outsourced, the operating unit is whoever the contract says it is — the contract must spell out responsibility for data governance and access control — instead of the old default that the service provider was the operator.

Who signs off

Assessment and approval follow the level, per Điều 18:

Level Assessed by Approved by
1–2 the owner’s specialised cybersecurity unit the same unit
3 the owner’s specialised cybersecurity unit the system owner
4 Bộ Công an (lead), with Bộ Quốc phòng and Ban Cơ yếu Chính phủ where relevant the system owner
5 Bộ Công an (lead) the Prime Minister, via the national-security list

The institutional shift is the middle column. Under Nghị định 85/2016 the assessor for Levels 4 and 5 was the Bộ Thông tin và Truyền thông, and its Cục An toàn thông tin kept the list of critical systems, updated quarterly. Now Bộ Công an assesses the top two levels and maintains the list, updating it annually by 15 January on its own portal; military and state-security systems are excluded from that list. Review clocks are mostly unchanged: at most 15 working days for a Level 3 assessment, 25 working days for Levels 4 and 5 (down from 30), and 7 working days for approval.

What owners must do

The “chủ quản hệ thống thông tin” carries direct responsibility. It must establish or designate an “đơn vị chuyên trách về an ninh mạng” (the old decree called it an information-safety unit), submit the classification dossier, put the approved protection plan in place before the system goes live, and run a risk assessment at four moments: initial classification, a change of function or technology, an expansion of scope, or after a serious incident. Management and technical measures are set out in Điều 29 and Điều 30 and cover policy, personnel, secure design, operational controls, monitoring, backup and incident response for every level. Duane Morris’s summary adds that Levels 3 and 4 hosted in cloud or data-centre environments must be logically segregated, while Level 5 requires physical segregation of systems, storage and core network equipment plus an independent assessment by a licensed enterprise.

Incident reporting gets fixed clocks under Điều 31: an initial notice within 24 hours of detecting a serious incident, a report on causes and handling within 72 hours, and immediate reporting where an incident shows signs of infringing national security.

The deadline that is already running

Điều 39 gives systems that existed or were under construction before 1 July 2026 six months from the law’s entry into force to complete assessment and approval of their level, and twelve months to meet the new conditions, standards and measures. Counted from 1 July 2026, that puts the classification deadline at 1 January 2027 and the compliance deadline at 1 July 2027. Organisations that classified their systems under Nghị định 85/2016 do not get to keep those decisions; they must re-run the exercise against the new criteria and, for Levels 4 and 5, with a different ministry.

Who it affects

Every state agency, obviously. But the Level 2 and Level 3 criteria are written around online services, personal data volumes, conditional business lines and shared infrastructure, which puts private operators squarely in scope: e-commerce platforms, banks and payment intermediaries, telecoms, hospitals, schools, SaaS vendors serving Vietnamese customers, and the cloud and data-centre providers hosting them. For those companies the decree is the operational half of a pair — Nghị định 330/2026/NĐ-CP, issued the same day, supplies the fines for not doing what this decree requires.

Practical implications

Inventory first. Most organisations will find that the hard part is not the paperwork but deciding what counts as one system, because the anti-fragmentation rule removes the option of splitting a platform into a dozen small “Level 2” pieces. Count data subjects, not accounts, and count sensitive data separately. Re-read outsourcing and cloud contracts: if they are silent on who the operating unit is and who controls access, they now need an amendment. Budget for Bộ Công an’s review if any system plausibly reaches Level 4, and for an independent assessment if it reaches Level 5. And put 1 January 2027 on the calendar.

Open questions

The published summaries do not say how the decree treats systems already approved at a given level under Nghị định 85/2016 beyond the general transition rule, nor how a single national list maintained by Bộ Công an interacts with the parallel classification of military systems. The definition of “sensitive personal data” is borrowed from the data-protection law, so a company’s Level 2 or Level 3 status will depend on how strictly that term is read. And the new 100,000 threshold means some systems will move down a level; whether they may relax controls they already have in place, or whether a risk assessment will push them back up, is a judgment the decree leaves to the owner.

Also issued this week

The Government’s daily bulletin for 5 September 2026 reported Nghị định 342/2026/NĐ-CP, detailing the Luật Thương mại and Luật Quản lý ngoại thương on goods trading by foreign investors and foreign-invested enterprises. Among the activities requiring a Giấy phép kinh doanh it lists the management and operation of intermediary e-commerce platforms, social networks with e-commerce functions and integrated e-commerce platforms; where a foreign investor controls one classed as a “nền tảng số lớn” (large digital platform), the provincial licensing authority must first obtain opinions from Bộ Công an and Bộ Quốc phòng on national security. The coverage so far does not state its effective date or confirm which earlier decree it replaces, so treat those points as pending.

Sources

This post is general information, not legal advice.