Who May Sell Cybersecurity in Việt Nam: Nghị định 332/2026/NĐ-CP Puts Vendors, SOCs and Bug-Bounty Platforms Under a Bộ Công an Licence

For ten years, a company that wanted to sell firewalls, run penetration tests or operate a security operations centre in Việt Nam needed one piece of paper: a Giấy phép kinh doanh sản phẩm, dịch vụ an toàn thông tin mạng, issued under Nghị định 108/2016/NĐ-CP by Bộ Thông tin và Truyền thông. That regime lost its legal footing on 1 July 2026, when the Luật An toàn thông tin mạng 2015 was repealed by the consolidated Luật An ninh mạng. Seven weeks later the Government issued its replacement. Nghị định 332/2026/NĐ-CP keeps the familiar shape — a ten-year licence, a separate permit for imports — but moves the licensing desk permanently to Bộ Công an, attaches hard headcount and nationality thresholds to the conditions, and draws new categories such as VPN-style IP masking and bug-bounty platforms into the licensed perimeter.

What the document is

Nghị định 332/2026/NĐ-CP “quy định về hoạt động kinh doanh sản phẩm, dịch vụ an ninh mạng” was issued by the Government on 19 August 2026, signed by Deputy Prime Minister Phạm Gia Túc on the Government’s behalf, on the proposal of the Minister of Public Security. Its legal bases are the Luật Tổ chức Chính phủ số 63/2025/QH15, the Luật An ninh mạng số 116/2025/QH15, the Luật Đầu tư số 143/2025/QH15 and the Luật Quản lý ngoại thương số 05/2017/QH14. Điều 1 says it details khoản 3 Điều 28 and khoản 3 Điều 29 of the cybersecurity law — the clauses that list cybersecurity products and services and tell the Government to regulate their licensing, import and export. It was one of the batch of cybersecurity decrees issued the same day, alongside Nghị định 330 (fines), 331 (system security levels) and 333 (general implementing rules).

The text has four chapters and 22 articles, followed by Phụ lục I with a dozen application and decision forms and Phụ lục II, a table of HS codes for the products that need an import or export permit. Điều 20 sets the effective date at 19 August 2026, the day of signing. Khoản 2 Điều 1 carves out civil cryptography, which is handled separately by Nghị định 341/2026/NĐ-CP and Ban Cơ yếu Chính phủ.

The parent law itself was passed on 10 December 2025 and took effect on 1 July 2026, repealing both the Luật An toàn thông tin mạng số 86/2015/QH13 and the Luật An ninh mạng số 24/2018/QH14. Điều 29 of the law states the core rule in one sentence: “Doanh nghiệp kinh doanh sản phẩm, dịch vụ an ninh mạng phải có giấy phép kinh doanh sản phẩm, dịch vụ an ninh mạng.” Everything else is in the decree.

What counts as a cybersecurity product or service

Điều 28 of the law lists generic categories; the decree fills in the “other” boxes. Under Điều 3, cybersecurity products fall into four groups: assessment products that scan configurations and logs and find vulnerabilities; monitoring products that analyse traffic and logs in real time and raise alerts; anti-attack and anti-intrusion products; and a fourth group of “sản phẩm an ninh mạng khác” that is new in its explicitness — covert information-collection tools, wireless-signal suppression and jamming equipment, digital-forensics and investigation tools, “network suppression” products that alter the operation of telecom or computer networks, and “sản phẩm che giấu địa chỉ IP”, products that route a device through a remote server to hide its real IP address.

Điều 4 lists eight groups of services: assessment, non-cryptographic information security, consulting, monitoring, incident response, data recovery, attack prevention, and a catch-all “dịch vụ an ninh mạng khác” with four named members. Two of those are straightforward — platforms that connect security experts and communities to defence tasks, and training and drill services. The other two matter for the tech industry: “dịch vụ che giấu địa chỉ IP trên không gian mạng”, the service form of a VPN or proxy, and “dịch vụ săn tìm và báo cáo lỗ hổng bảo mật”, a platform that receives vulnerability reports from researchers on behalf of organisations — in other words, a bug-bounty or vulnerability-disclosure platform. Under Điều 5, any organisation doing business in a listed product or service needs the licence, which runs for ten years.

What changed compared with the 2016 regime

Nghị định 108/2016/NĐ-CP, signed by Prime Minister Nguyễn Xuân Phúc on 1 July 2016, required a licence from Bộ Thông tin và Truyền thông, valid for ten years, decided within 40 working days under Điều 44 of the 2015 law. Its personnel condition was qualitative: technical staff with a university degree or a certificate in information security, IT or telecoms, “with a number meeting the scale and requirements of its business plan”. There was no headcount floor, no nationality rule and no special condition for foreign-invested companies.

The licensing desk had in fact already moved. On 28 February 2025, in the reorganisation of ministries, Bộ Thông tin và Truyền thông formally handed ten administrative procedures — including issuing, renewing and amending the business licence and the import licence for network-information-security products — to Bộ Công an, whose Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao took them over from 1 March 2025. Nghị định 332 gives that arrangement its own rulebook and makes several substantive changes:

  • Faster decision, thinner file. Bộ Công an must decide within 28 working days of a complete file, down from 40. The file is one set, in Vietnamese, submitted in person, by post or through the online public-service portal with a digital signature. Completeness is checked within three working days, and applicants get ten working days to fix gaps.
  • Numeric staffing floors. Under Điều 8, assessment and consulting providers need at least five technical staff with a university degree or a cybersecurity certificate, each with a specific residential address in Việt Nam; monitoring providers need at least twelve, plus a named person responsible for system administration and information security. In both cases the legal representative must be a Vietnamese national.
  • Foreign-invested companies. Điều 6 requires that a foreign-invested economic organisation have more than five years of investment term remaining in Việt Nam, counted from the licence date.
  • Vetting of managers. Legal representatives and managers may not be under prosecution or carry an unexpunged conviction for national-security offences or other intentional crimes, and overseas Vietnamese holding foreign passports or foreigners without a Vietnamese residence or work permit are excluded from those roles.
  • A reserved list. Under Điều 7, the covert-collection, jamming, forensics and network-suppression products in khoản 4 Điều 3 may be produced, traded, imported or exported only by organisations and enterprises of Bộ Công an or Bộ Quốc phòng acting on a tasking document, or by companies holding a contract with a competent agency of those ministries, and only for national-security missions. IP-masking products are notably not on the reserved list.
  • A live link to the state. Điều 16 obliges monitoring-service providers to maintain a connection and exchange monitoring information with Bộ Công an’s national cybersecurity-protection system while providing the service.
  • Per-shipment import permits. Under Điều 13, products on the Phụ lục II list — some two dozen lines identified by HS codes in headings 8471, 8517.62 and 8525.60, from endpoint and mobile-device protection through network access control, network firewalls, intrusion detection and prevention, anti-DDoS, VPN, application-layer security, data-loss prevention and storage security to information-collection devices — need a Giấy phép xuất khẩu, nhập khẩu issued per shipment, valid for two years, within five working days. The importer must already hold the business licence, show that the product meets an international or Vietnamese standard, and document the end user and purpose.

Keeping the licence

Amendments (cấp đổi) and re-issues take five working days. An extension is available once, for no more than three years, on an application filed at least 60 days before expiry with a report on the last two years’ activity; Bộ Công an decides within ten working days. Điều 14 lists five grounds for outright revocation — falsified documents, failure to restore compliance within 40 days of a demand, no activity six months after issuance, dissolution or bankruptcy, and lending, renting or selling the licence — and five grounds for a three-to-six-month suspension, including failure to file the annual report and two administrative penalties within twelve months. Revocation and suspension decisions go to the business-registration office and to customs, and they void any outstanding import permits. Inspections are capped at one comprehensive check per year unless there are clear signs of a violation. Licence holders must file an annual report by 31 January for the preceding calendar year and give ten working days’ notice of any suspension of operations.

For holders of the old Bộ Thông tin và Truyền thông licence, two texts work together. Khoản 2 Điều 45 of the law says licences for network-information-security products and services issued before 1 July 2026 “có giá trị sử dụng đến hết thời hạn được ghi trên giấy phép”. Khoản 3 Điều 10 of the decree then provides a conversion table for anyone who amends their licence: assessment, monitoring, consulting and incident-response lines are renamed to their “an ninh mạng” equivalents, anti-attack products and services, data recovery and non-cryptographic security are kept as they are, and the old catch-all lines “sản phẩm an toàn thông tin mạng khác” and “dịch vụ an toàn thông tin mạng khác” are simply removed. The converted licence keeps the original term.

Who is affected, and what to do

Established security vendors and managed-service providers. The former ministry’s public roster of licence holders already ran to 61 names by mid-2019, including Viettel, VNPT, FPT, BKAV and CMC. For them the licence itself survives, but the twelve-person floor for monitoring, the mandatory feed to the national protection system and the once-only three-year extension change the operating and renewal calendar. A ten-year licence issued in 2018 runs to 2028, can be stretched to 2031, and then requires a fresh application under the new conditions.

Small consultancies and pentest boutiques. Five qualified staff resident in Việt Nam and a Vietnamese legal representative is a real threshold for a three-person shop or a foreign-led advisory firm. Firms below it will need to hire, partner or restructure before their current licence lapses.

Bug-bounty platforms and VPN providers. Both are now named as licensable services. A Vietnamese entity operating a vulnerability-disclosure marketplace should treat itself as inside the perimeter. How the rule reaches foreign VPN services with no Vietnamese establishment is not addressed; the decree regulates “kinh doanh” by organisations and enterprises, and enforcement against offshore providers would have to come through other instruments.

Foreign-invested companies. Beyond the five-year investment-term test, the nationality rule for legal representatives of service providers and the reserved list for surveillance and forensics tools shape what a foreign group can offer directly and what it must route through a Vietnamese partner or a contract with Bộ Công an or Bộ Quốc phòng.

Importers and distributors. Classification work comes first: matching each product against the HS lines in Phụ lục II, then securing the per-shipment permit and the end-user documentation before goods reach customs.

Buyers. Procurement teams should ask for the vendor’s licence number and check the listed lines cover what is being bought. The reserved list also means an ordinary company cannot lawfully buy jamming or covert-collection tools from a commercial vendor.

Open questions

Khoản 2 Điều 21 says applications that Bộ Công an received before 1 July 2026 and had not yet resolved are processed under the new decree — presumably the files it inherited in March 2025 — but does not say how an application drafted to the old qualitative staffing standard is judged against the new headcounts. Điều 7 requires that a producer’s product range and scale be “phù hợp với chiến lược phát triển ngành công nghiệp an ninh mạng”, without identifying the strategy document or the assessment method. The fee schedule is delegated to the law on fees and charges and has not been published. And products that combine cryptographic and cybersecurity functions still face two licensing tracks, this one and Nghị định 341, with no single window between Bộ Công an and Ban Cơ yếu Chính phủ.

Sources

This post is general information, not legal advice.