Nine days before this was written, a short circular from the Ministry of National Defence quietly answered a question that had been hanging over Việt Nam’s encryption vendors all year: exactly which cryptographic products fall into the top tier of the country’s new risk-based product-quality regime, and what a company has to do about it. Thông tư 126/2026/TT-BQP is seven pages long, has seven articles, and does almost all of its work in a three-row appendix.
What the document is
Thông tư 126/2026/TT-BQP issues the Danh mục sản phẩm mật mã dân sự có mức độ rủi ro cao — the list of high-risk civil cryptography products within the Minister of National Defence’s remit — together with their HS codes and the corresponding quality-management requirements. It was signed in Hà Nội on 2 September 2026 by Bộ trưởng Bộ Quốc phòng, Đại tướng Phan Văn Giang, at the proposal of Trưởng ban Ban Cơ yếu Chính phủ, and Điều 6 sets it in force from the same day, 2 September 2026. (The digital signature on the published copy was applied on 3 September.) Việt Nam’s law-making statute normally requires a central-level document to wait at least 45 days after signing before taking effect, with an exception for documents issued under the simplified procedure, which may take effect on the date of signing — so the same-day start places this circular in that second category.
Its legal foundations run across four statutes: Luật Cơ yếu số 05/2011/QH13, the Luật Chất lượng sản phẩm, hàng hóa số 05/2007/QH12 as amended by Luật số 35/2018/QH14 and Luật số 78/2025/QH15, the Luật Tiêu chuẩn và quy chuẩn kỹ thuật số 68/2006/QH11 as amended by Luật số 35/2018/QH14 and Luật số 70/2025/QH15, and Luật An ninh mạng số 116/2025/QH15. Below those sit Nghị định 37/2026/NĐ-CP of 23 January 2026 on product quality and Nghị định 22/2026/NĐ-CP on standards and technical regulations.
What is actually on the list
The appendix has three numbered entries, all classified high risk:
- IP-stream security products using IPsec and TLS. Devices and security software implementing secure virtual private networks — IPsec VPN and TLS VPN — that encrypt, decrypt, digitally sign or authenticate data in transit, for information outside the scope of state secrets. Governed by QCVN 12:2022/BQP together with its 2026 amendment (Sửa đổi 1:2026).
- Stored-data security products. Products that encrypt or decrypt data at rest: smart cards, USB tokens, integrated-circuit memory, purpose-built storage systems, and cloud storage. Governed by QCVN 15:2023/BQP and its 2026 amendment.
- Civil cryptography products used in banking. Products that encrypt, decrypt, sign or authenticate data in transit, in receipt or at rest for banking use. Governed by QCVN 4:2026/BQP, QCVN 5:2016/BQP and QCVN 6:2016/BQP.
The two amended standards and the new QCVN 4:2026/BQP — which replaced QCVN 4:2016/BQP on data encryption in banking — were issued by Thông tư 07/2026/TT-BQP of 20 January 2026, effective 6 March 2026.
Each entry carries a long column of HS codes drawn from the Vietnamese import–export nomenclature: 8471.30.90, 8471.41.90 and 8471.49.90 for data-processing machines; the 8517.62.xx range for network and telecoms apparatus; 8523.51.11 through 8523.52.00 for solid-state storage and smart cards; 8542.32.00 for memory ICs; and, for the banking group, additional codes including 8525.50.00, 8525.60.00, the 8526.9x transmission-apparatus range and several 8443.3x printing codes.
What the requirements are
For every item on the list the management requirement is the same three-part formula. First, công bố hợp quy — a declaration of conformity — made on the basis of a conformity certificate issued by a designated certification body, not a self-declaration. Second, the conformity-assessment method must be phương thức 5 or phương thức 7 under Thông tư 14/2026/TT-BKHCN of 9 April 2026: method 5 certifies a product type through testing of a representative sample plus assessment of the production process or management system, and is valid for up to five years with ongoing surveillance; method 7 certifies a single batch through testing of samples drawn from it, with no follow-up surveillance. Third, imported goods are subject to state quality inspection.
Điều 3 adds a further constraint that matters to laboratories and importers alike: the test results underpinning a conformity certificate must come from a testing organisation designated by the Minister of National Defence, or one recognised under standards law, and the lab’s testing scope must match the relevant national technical regulation.
Điều 4 handles overlaps. Where a product falls under two or more national technical regulations it must satisfy all of them, while avoiding duplicate assessment of the same technical requirement already assessed against a corresponding regulation. Where a technical regulation issued before this circular sets a different quality-management requirement for a listed product, the circular prevails. Where a regulation is newly issued, amended or replaced later, the later instrument governs from its own effective date.
What changes compared to before
The shift underneath this circular is the one made by Luật số 78/2025/QH15, passed on 18 June 2025 and in force since 1 January 2026, which replaced the old “nhóm 1 / nhóm 2” split in the product-quality law with three risk levels — low, medium and high — and pushed the whole system towards risk management and post-market inspection. Every line ministry has had to re-express its old “group 2” list in the new taxonomy; Bộ Khoa học và Công nghệ did so in Thông tư 36/2026/TT-BKHCN, Bộ Công an in Thông tư 125/2026/TT-BCA (effective 1 July 2026), and Bộ Quốc phòng has now done it for civil cryptography.
Two things are genuinely new rather than relabelled. The list now carries HS codes aligned to the customs nomenclature, which moves the classification question out of technical argument and into the tariff line a shipment is declared under. And the conformity-assessment method is pinned to the Thông tư 14/2026/TT-BKHCN framework, where the maximum certificate life for method 5 was extended to five years and surveillance intervals are set by risk level — for high risk, no more than 12 months between checks.
There is also a notable subtraction. The draft circular the Ministry put out for comment in mid-2026, with feedback closing on 3 July, was framed around products at both medium and high risk. What was finally issued covers only the high-risk tier.
Who it affects and what to do
Điều 2 names two groups: organisations and individuals that manufacture, trade in or import listed high-risk products, and the agencies and parties involved in managing their quality. In practice that means VPN and network-security appliance vendors, HSM and secure-element suppliers, encrypted-USB and smart-card makers, cloud storage providers with encryption at rest, and the banking technology supply chain — card personalisation, PIN and key management, secure printing.
The deadline to diarise is in Điều 5 khoản 2: products on the list that were already licensed and circulating on the market have 24 months from the circular’s effective date — that is, until 2 September 2028 — to meet the corresponding quality-management requirements. Nothing is pulled from shelves immediately, but the runway is finite, and certification under method 5 involves a factory assessment that takes planning.
This sits on top of, not instead of, the licensing regime in Nghị định 341/2026/NĐ-CP of 1 September 2026, whose Điều 4 already required civil cryptography products to be certified for conformity before circulating. A vendor may therefore need three things at once: a business licence for civil cryptography, an import/export permit where the product appears on that decree’s Phụ lục II, and now a conformity certificate under a designated body for anything matching an entry here. Ban Cơ yếu Chính phủ is the body responsible for inspecting, guiding and proposing amendments to the list.
Open questions
The circular does not publish the roster of designated testing and certification organisations, so the practical bottleneck — how many labs can test against QCVN 12, 15 and 4 and how long a queue forms before September 2028 — is not answerable from the text. Nor is it clear what happens to cryptographic products that fall outside all three entries: with no medium-risk list issued for this sector, a product that is neither listed nor exempted sits in an unlabelled space. The same-day effective date leaves no notice period, though the 24-month transition absorbs most of that for goods already on the market. And because the appendix ties products to HS codes, borderline devices that combine encryption with other functions will be classified in practice by customs declarations as much as by technical specification.
Sources
- Thông tư số 126/2026/TT-BQP ban hành Danh mục sản phẩm mật mã dân sự có mức độ rủi ro cao — Xây dựng chính sách, Cổng TTĐT Chính phủ
- Toàn văn Thông tư số 126/2026/TT-BQP (PDF, Cổng TTĐT Chính phủ)
- Thông tư 07/2026/TT-BQP: Quy chuẩn kỹ thuật mật mã dân sự — LuatVietnam
- Thông tư số 14/2026/TT-BKHCN về công bố hợp chuẩn, công bố hợp quy và phương thức đánh giá sự phù hợp — Công báo Chính phủ
- Nghị định số 37/2026/NĐ-CP quy định chi tiết Luật Chất lượng sản phẩm, hàng hóa — Công báo Chính phủ
- Luật số 78/2025/QH15 sửa đổi, bổ sung một số điều của Luật Chất lượng sản phẩm, hàng hóa — Công báo Chính phủ
- Siết chặt an toàn qua danh mục mật mã dân sự rủi ro cao (dự thảo, hạn góp ý 3/7/2026) — Luật Nguyễn
- Thông tư 125/2026/TT-BCA ban hành Danh mục sản phẩm, hàng hoá có mức độ rủi ro trung bình, rủi ro cao
- Về thẩm quyền ban hành và hiệu lực của văn bản quy phạm pháp luật theo Luật Ban hành văn bản quy phạm pháp luật năm 2025 — Tạp chí Quản lý nhà nước
This post is general information, not legal advice.