A Licensing Regime by Customs Code
On August 19, 2026, Vietnam's government brought Decree 332/2026/ND-CP into force, creating a formal licensing regime — administered by the Ministry of Public Security (MPS) — for anyone manufacturing, importing, exporting, or trading "cybersecurity products and services" in the country. The decree runs four chapters and 22 articles, and licenses it issues are valid for ten years, with a statutory 28-working-day review period once a complete application is filed, according to legal analysis from Duane Morris.
The mechanism that makes this decree unusually far-reaching is not a product definition — it's an HS (Harmonized System) customs code list. Rather than naming "firewalls" or "intrusion-prevention systems" as regulated categories and leaving networking hardware alone, the decree ties licensing obligations to specific tariff classifications. Under codes 8517.62.43 and 8517.62.49, routers, switches, gateways, and similar IP networking devices fall within scope whenever they provide IP security or secure network communication functions — which, in practice, is most modern enterprise and consumer connectivity hardware, since encrypted tunneling, access-control lists, and basic packet filtering are now standard features rather than premium add-ons. IoT security devices are captured under a parallel set of computer-equipment codes.
The Case for Doing This
Vietnam's rationale deserves a fair hearing before it gets a rebuttal. Connected devices are a genuine attack surface: cheap, unpatched routers and IoT gateways are the backbone of botnets like Mirai, and a government overseeing critical national infrastructure has a legitimate interest in knowing which vendors are selling security-relevant hardware into its networks, under what technical standards, and with what supply chain. Vietnam's parallel Circular 48/2026/TT-BCA, which set baseline IoT cybersecurity requirements for IP cameras anchored to the ETSI EN 303 645 standard, showed the government is capable of writing narrowly scoped, internationally aligned device rules. A licensing regime that screens out fly-by-night vendors of genuinely security-marketed products — VPN appliances, DDoS mitigation boxes, monitoring platforms — is not obviously unreasonable, and MPS's ten-year license term is at least generous by regional standards.
Where Proportionality Breaks Down
The problem is the HS-code trigger, not the underlying goal. Tariff codes were built to classify goods for customs valuation, not to distinguish a consumer-grade home router with a built-in firewall toggle from a purpose-built network intrusion prevention appliance. By routing licensing scope through 8517.62.43/8517.62.49 rather than through a functional or risk-based test, the decree sweeps in equipment that was never marketed, priced, or engineered as a security product — it just happens to ship with the IPsec or stateful-inspection features that are now baseline in any router sold anywhere. That is a much larger and more heterogeneous population of importers and manufacturers than the decree's own stated targets (assessment, monitoring, anti-attack, and specialized cybersecurity products), and it is precisely the kind of over-inclusive drafting that turns a security screen into a market-access bottleneck.
The compliance mechanics compound the problem. A 28-working-day review is workable for a firm that plans annual product launches; it is a real obstacle for hardware companies that iterate on firmware and hardware revisions continuously, since each new HS-classified SKU risks re-triggering review. Import/export activity additionally requires separate MPS shipment licenses valid for only two years — a shorter clock than the underlying business license, meaning networking-equipment importers face two overlapping renewal cycles rather than one.
The Foreign-Investor Wrinkle
For foreign-invested enterprises, the decree adds a condition with no obvious cybersecurity rationale: a licensee's remaining investment-project term in Vietnam must exceed five years at the time of license issuance. That requirement screens on corporate runway, not technical competence or security posture, and it will disproportionately hit newer market entrants and firms operating under shorter-term investment certificates — exactly the smaller, less-established vendors who most need a level playing field against incumbents with decades-old licenses.
Widely deployed networking equipment — including routers, switches, gateways, and similar IP networking devices — can fall within the regulatory scope when they provide IP security or secure network communication functions.
The Fix Is Narrower Scoping, Not Repeal
Vietnam does not need to abandon device-security oversight to fix this. It needs to replace the blunt HS-code trigger with a functional test — does the product's primary marketed purpose involve security monitoring, threat detection, or attack mitigation — the same distinction its own Circular 48 already draws for IP cameras. Absent that fix, Decree 332 risks doing to routers and IoT gateways what an overbroad classification always does: taxing the compliant mainstream to catch a small population of bad actors, while raising the cost of connectivity hardware for every business and household in Vietnam's market.