Việt Nam's New Cybersecurity Decrees: Nghị định 333 and 327 Take Effect

Việt Nam’s consolidated cybersecurity regime just grew teeth. On 19 August 2026, the Government issued two implementing decrees under the new Law on Cybersecurity — Nghị định 333/2026/NĐ-CP and Nghị định 327/2026/NĐ-CP — and both took effect the same day. Together they translate the law’s broad principles into concrete obligations, deadlines measured in hours, and account-level sanctions. Anyone operating an online service that reaches Vietnamese users should be reading them closely.

The parent law, briefly

The decrees implement Luật An ninh mạng số 116/2025/QH15, passed on 10 December 2025 and in force since 1 July 2026. That law merged two older frameworks — the 2015 Law on Cyberinformation Security (86/2015/QH13) and the 2018 Law on Cybersecurity (24/2018/QH14) — into a single statute of 8 chapters and 45 articles, with new provisions aimed at fraud and false information spread using AI and other emerging technologies. Like most Vietnamese framework laws, it left the operational detail to implementing decrees. This is that detail arriving.

Nghị định 333/2026/NĐ-CP: the operational rulebook

The larger of the two decrees runs to six chapters and 32 articles, covering cybersecurity protection measures, information security assurance, specialised cybersecurity training, and management of IP address identification for telecommunications and Internet service providers. The obligations that will matter most in practice:

  • Real-identity accounts. Domestic and foreign service providers must verify users’ information when digital accounts are registered — and authenticate accounts using a Vietnamese mobile phone number. Since local SIMs are themselves identity-verified, this effectively ends anonymous account registration on in-scope services.
  • Data provision on the clock. Valid requests from cybersecurity authorities for user information must generally be answered within 24 hours — compressed to 3 hours in emergencies involving national security or threats to human life.
  • Takedowns on the clock. Illegal information, services, and applications must be restricted or removed within 24 hours, or 6 hours for national-security emergencies.
  • Log retention. System logs — user account information, login and logout times, IP addresses, source ports — must be stored and managed for at least 12 months.
  • Graduated account sanctions. Accounts posting illegal content three or more times within 30 days face restrictions of up to 60 days; ten or more times within 90 days, up to 180 days; national-security violations or persistent recidivism can mean an indefinite block.

Nghị định 327/2026/NĐ-CP: handling threats in cyberspace

The companion decree details Article 14 of the law — the prevention and handling of information and activities in cyberspace that threaten national security or social order. Information system operators and service providers must electronically identify and authenticate users before and during service provision, detect and block unregistered accounts, proactively monitor and remove threatening information, and report within 24 hours any cyberattack affecting sovereignty or security. Authorities’ toolkit includes service blocking, content removal, domain name revocation, and access restrictions. Notably, the decree also carries a protective strand: providers must warn users about fraud and privacy violations, with particular attention to children, minors, older people, and people with disabilities.

Who is affected, and what to do

The scope is explicitly not limited to Vietnamese companies: foreign businesses providing services on telecommunications networks, the Internet, or value-added services in Vietnamese cyberspace are covered. For anyone running a platform, app, or online community with Vietnamese users, the practical checklist looks like this: build (or buy) phone-number-based verification for Việt Nam; stand up an on-call process capable of hitting 24/6/3-hour response windows; audit whether your logging actually captures the required fields, and whether you can retain it for 12 months in a way that also respects the Personal Data Protection Law; and map an escalation path for government requests.

The open questions are familiar ones: how vigorously the rules will be enforced against offshore providers with no Vietnamese presence, and how the account-violation counting will work across services in practice. Both decrees are new enough that the first enforcement actions will be the real guidance.

Sources

This post is general information, not legal advice.