Vietnam's 2025 Cybersecurity Law: 5-level system classification and what to do

Photo: Kevin Ache / Unsplash
From 1 July 2026, Vietnam's 2025 Cybersecurity Law (No. 116/2025/QH15) takes effect. This is not a minor amendment: it consolidates and replaces the old legal framework, resetting how the state and businesses classify and protect information systems. For IT and security teams, it is a milestone that forces a full review.
What's new
Per EY's legal update, the 2025 Cybersecurity Law No. 116/2025/QH15 (passed 10 December 2025, effective 1 July 2026) establishes a unified legal framework for cybersecurity and information security. The three biggest changes:
- Merging two laws. The new law consolidates the 2015 Law on Cyber-Information Security and the 2018 Law on Cybersecurity into a single framework, ending the overlap between "information security" and "cybersecurity".
- First codification of "data security". Data is treated as an independent object of protection, not merely an appendage of a system.
- Classifying information systems into 5 security levels. This is the central provision, and it directly determines each organization's obligations.
What the "5 levels" mean
Per LuatVietnam, a central provision of the law classifies information systems into five security levels, on the principle that the more important a system is and the more severe the consequences if attacked, the higher its level — and the stricter the required protection.
In other words, the law no longer applies one blanket protection standard to every system. A brochure website and a large-scale citizen-data system carry different obligations. The criteria for determining levels and the corresponding measures will be detailed in implementing decrees and circulars — businesses should track these to apply the right standard.
The key point for organizations: you must classify your own systems by level, then apply the corresponding protection — rather than waiting for an inspection to act.
What businesses should do
- Inventory and classify systems. List the information systems in operation and make an initial level determination based on importance and the data they process.
- Assess the gaps. Compare current protections against the requirements for each level; find what's missing (monitoring, access control, encryption, backups, incident response).
- Prioritize high-level systems. Systems handling sensitive data or critical to operations need investment first — web/API firewalls, monitoring, access control.
- Tie it to data obligations. The law's "data security" resonates with the personal-data protection duties of the 2025 PDPL — review them together, not separately.
- Prepare coordination procedures. Have a point of contact and a reporting/response process ready for when authorities make a request.
Why this is an opportunity, not just a burden
Level-based classification actually helps businesses spend security budget where it matters: not spreading money thin, but concentrating resources on genuinely important systems. An organization that takes classification seriously both complies and optimizes its security spend.
For high-level systems — especially internet-facing ones like service portals, APIs and web apps — a web-and-API protection layer (WAAP) plus centralized monitoring is a practical foundation for meeting level-based requirements.
Conclusion
The 2025 Cybersecurity Law shifts cybersecurity from "box-ticking" to "by risk level". Organizations that proactively inventory, classify and close gaps before 1 July 2026 will be less exposed when detailed guidance and inspection mechanisms come into force.
If you want to review your systems' security levels and strengthen application and API defenses, book a consultation to assess against your actual infrastructure.
Related articles

Securing Dokploy: adding a WAF and IPS on the server itself
A default Dokploy install runs fine but is not safe: Traefik is not a WAF, Docker bypasses UFW, DNS-only domains leak the origin IP. Three gaps and how to close them on your own host.
Read ↗
Hansoll hit by ransomware: how manufacturing and FDI firms defend
The ransomware case targeting Hansoll Textile shows manufacturing and FDI firms are also targets. Practical defense lessons for manufacturers.
Read ↗
Two ministry systems breached, SOC "blind": why modern monitoring matters
At Vietnam Security Summit 2026, the cyber agency disclosed two ministry-level incidents that on-site SOCs missed. Lessons on monitoring and protection.
Read ↗Personal Data Protection checklist
Review your business before the law takes effect on 01/01/2026.