Selling Encryption in Việt Nam Has a New Rulebook: Nghị định 341/2026/NĐ-CP on Civil Cryptography

Encryption is inside almost everything a company buys today — VPN appliances, hardware security modules, encrypted storage, secure messaging, PKI tokens. In Việt Nam, trading in those products has been a licensed activity for a decade, but the law that underpinned the licences, Luật An toàn thông tin mạng 2015, was repealed on 1 July 2026 when the consolidated Luật An ninh mạng took over. For two months the licensing regime for mật mã dân sự (civil cryptography) ran on a decree whose parent law no longer existed. That gap closed on 1 September 2026 with Nghị định 341/2026/NĐ-CP, the first implementing decree on civil cryptography under the new cybersecurity law.

What the document is

Nghị định 341/2026/NĐ-CP was issued by the Government on 1 September 2026 and took effect the same day. It details điểm a khoản 1, điểm c khoản 2 and khoản 3 of Điều 28, and khoản 3 of Điều 29, of Luật An ninh mạng số 116/2025/QH15 — the law passed on 10 December 2025 and in force since 1 July 2026, which replaced both Luật An toàn thông tin mạng 2015 and Luật An ninh mạng 2018. The decree covers what counts as a civil cryptography product or service, the conditions for trading in them, import and export, and the full lifecycle of the two relevant licences: issuance, amendment, suspension and revocation. Three appendices follow the articles: Phụ lục I lists the products and services that require a business licence, Phụ lục II lists the products that require an import/export permit, and Phụ lục III holds the forms.

The decree was drafted on the defence side of government. Ban Cơ yếu Chính phủ (the Government Cipher Committee), which sits under Bộ Quốc phòng, remains the licensing authority. The Prime Minister’s implementation plan for the law, Quyết định 437/QĐ-TTg of 16 March 2026, had asked the Ministry of National Defence to deliver its civil-cryptography decrees before 1 July 2026, so this one arrived two months behind schedule.

It takes over from Nghị định 58/2016/NĐ-CP of 1 July 2016, as amended by Nghị định 53/2018/NĐ-CP and Nghị định 32/2023/NĐ-CP, which had governed the sector since the 2015 law came into force. A replacement had been in the works since Ban Cơ yếu Chính phủ proposed one in June 2023 and the Ministry of National Defence published a draft in June 2024; the new cybersecurity law finally gave it a home.

What the decree says

Definitions. Civil cryptography products are hardware, software, documents, technical equipment and cryptographic techniques used to protect information that is not a state secret. Civil cryptography services are information protection using such products, product assessment, and security consulting. Anything protecting state secrets belongs to a separate, classified regime.

Business licence. An enterprise trading in products or services listed in Phụ lục I needs a Giấy phép kinh doanh sản phẩm, dịch vụ mật mã dân sự, valid for 10 years. Under Điều 5 the applicant must have at least two technical staff with a university degree or higher in electronics-telecommunications, information technology, mathematics or information security, plus one manager holding a degree in one of those fields or a degree in another field together with an information-security training certificate. It must also have equipment and facilities matching the scope of what it sells, and a technical plan that meets applicable standards and technical regulations, spelling out product characteristics and parameters, the standards applied, quality metrics, technical solutions and warranty and maintenance arrangements.

Faster decisions. Ban Cơ yếu Chính phủ checks a dossier for completeness within one working day and must decide on a business licence within 12 days of receiving a complete file. The 2015 law allowed 30 days. Import/export permits are decided within 6 working days.

Import and export. Products in Phụ lục II need a Giấy phép xuất khẩu, nhập khẩu sản phẩm mật mã dân sự, valid for 3 years. The permit requirement bites only when the product’s HS code, description and cryptographic specifications all match an entry on the list, so classification matters. Products that combine cryptographic features with cybersecurity features are treated as dual-use: they go to Bộ Công an for approval, with Ban Cơ yếu Chính phủ consulted on the cryptographic side.

Conformity first. Điều 4 restates that civil cryptography products must be inspected and certified for conformity (chứng nhận hợp quy) before they circulate on the market.

Suspension and revocation. Điều 8 allows suspension of up to six months for non-compliance, and revocation where a licence was obtained with forged documents, has expired, or where the holder has not actually started supplying within a year without a valid reason.

Duties for licence holders. Enterprises must ensure product quality, protect customer information, refuse to supply a product or service when they detect it being used unlawfully, and report to Ban Cơ yếu Chính phủ before 31 December each year.

A duty for users too. Under Điều 12, organisations and individuals using civil cryptography products that were not supplied by a licensed enterprise must declare them to Ban Cơ yếu Chính phủ. Diplomatic and consular missions and international organisations in Việt Nam are exempt.

Transition. Điều 18 keeps licences issued before 1 July 2026 valid until the expiry date printed on them, so no existing vendor has to reapply.

What actually changes

The staffing conditions will look familiar to anyone who held a licence under Nghị định 58/2016: the two-technical-staff rule and the manager rule are carried over almost word for word, and the 10-year licence term is unchanged. The substance of the reform is procedural and structural. Decision times shrink from 30 days to 12, the completeness check gets a fixed one-day clock, revocation for “licence but no business” is spelled out, dual-use products get an explicit two-agency route, and the whole regime now hangs off the cybersecurity law rather than a repealed information-security law. The product lists in the appendices are where the real detail lives — the 2024 draft had proposed consolidating products into seven groups with twelve categories of excluded items — and companies should read them rather than assume the old lists carried over.

Who it affects

Vendors and distributors of encryption hardware and software in Việt Nam, from HSM and VPN appliance resellers to secure-messaging and PKI providers, remain licensed businesses and now have a shorter path to a licence. Importers and system integrators bringing in encrypted network gear must check HS codes against Phụ lục II and hold a 3-year permit where required. Foreign vendors selling into Việt Nam need a licensed local channel, since the licence attaches to an enterprise established in the country. Enterprises that source encryption products themselves — a bank importing HSMs directly, a company deploying tooling bought abroad — fall under the declaration duty in Điều 12. Security teams should know that this obligation exists even though the product is legal to use.

Practical implications

For licence holders the immediate task is confirmation, not reapplication: existing licences stand, but the annual report to Ban Cơ yếu Chính phủ now has a fixed year-end deadline. For new entrants the calculus improves — a 12-day decision makes it realistic to obtain a licence inside a normal procurement cycle. For importers the practical work is classification: matching HS code, description and cryptographic specification against Phụ lục II, and identifying products with both cryptographic and cybersecurity functions early, because those need Bộ Công an’s approval as well. For buyers, the declaration duty means procurement and security teams should record where encryption products came from and whether the supplier was licensed.

A companion decree in the same week

Three days later, on 4 September 2026, Báo Chính phủ reported Nghị định 343/2026/NĐ-CP, which details the parts of Luật An ninh mạng under the Ministry of National Defence’s remit and sets out how “xung đột thông tin trên không gian mạng” (information conflict in cyberspace) is received and handled. It assigns information-system owners the duty to receive and handle conflicts affecting their systems and to coordinate with the specialised cybersecurity forces; gives those forces the lead on analysing conflicts between domestic and foreign actors; and allows telecom and Internet providers to block traffic only once the source is identified, the affected party’s request is verified, and a written or system-generated order from the competent force exists. Its predecessor was Nghị định 142/2016/NĐ-CP of 14 October 2016. The coverage available so far does not state its effective date, so treat that as unconfirmed.

Open questions

The published summaries do not quote a repeal clause naming Nghị định 58/2016/NĐ-CP, so the formal fate of the old decree and its product lists should be read from the full text. The user-side declaration duty raises practical questions the decree does not answer — how it applies to encryption embedded in cloud services, to open-source tooling with no vendor at all, or to a laptop’s built-in disk encryption. The fee schedule and the exact content of Phụ lục I and II will determine how heavy the regime feels in practice. And the two-agency route for dual-use products will need coordination between Ban Cơ yếu Chính phủ and Bộ Công an, whose separate licensing of cybersecurity products under Chapter V of the same law is being built out in parallel through decrees like Nghị định 333/2026/NĐ-CP.

Sources

This post is general information, not legal advice.