A Law Written After a Bad Season of Ransomware
In the spring of 2024, Vietnam absorbed three ransomware hits in ten weeks. VNDirect, one of the country's largest brokerages, was knocked offline for days after an intrusion encrypted its systems, freezing trading for hundreds of thousands of investors. Eight days later, state-owned fuel distributor PVOIL disclosed a near-identical attack. By June, Vietnam Post was disconnecting its own network to contain a third incident. Each company responded under a legal patchwork split between the 2015 Law on Network Information Security and the 2018 Law on Cybersecurity — two statutes with overlapping jurisdictions and no single, mandatory clock for reporting an incident to the state.
That gap is now closed. The Law on Cybersecurity No. 116/2025/QH15, passed by the National Assembly on December 10, 2025, took effect July 1, 2026, merging the 2015 and 2018 laws into one framework administered by the Ministry of Public Security (MPS) (chinhphu.vn).
What the Law Actually Does
The statute sorts information systems into a five-tier severity classification, with the Prime Minister personally designating which systems in finance, energy, defense, and public administration count as critical to national security — triggering mandatory certification, continuous monitoring links to state cybersecurity agencies, and incident-response obligations (chinhphu.vn; Rajah & Tann Asia). Agencies running digital-transformation projects must now allocate a minimum 15% of budget to cybersecurity — equipment, incident-response services, and workforce training. And for the first time, the law explicitly criminalizes ransomware attacks, AI-generated deepfake impersonation, digital identity forgery, and supply-chain compromise as named offenses rather than leaving prosecutors to stretch older statutes to fit (bocongan.gov.vn).
The Case for Consolidation
The strongest argument for this law is that Vietnam was legislating for 2015-era threats with a 2015-era institutional map. Fragmented authority between two ministries meant no single agency owned incident response end-to-end, and no statute compelled a breached operator to report on a fixed clock. That is a genuine regulatory failure, and Vietnam is not alone in fixing it: the EU's NIS2 Directive imposes a 24-hour early-warning and 72-hour follow-up notification on critical-sector operators, and the US CIRCIA regime, which itself only took full effect this year, requires 72-hour incident reports and 24-hour ransom-payment disclosures from covered infrastructure entities. A national ransomware epidemic — CISA and the FBI reported this week that the Medusa gang alone has hit more than 500 victims as of April 2026, up from 300 a year earlier, exploiting newly disclosed vulnerabilities within 24 hours of announcement (The Record) — is exactly the kind of threat that justifies mandatory, fast reporting rather than voluntary best practice.
Where the Design Breaks Down
The problem is not that Vietnam mandated reporting. It's who it made the sole recipient. NIS2 routes incident reports to civilian CSIRTs and ENISA; CIRCIA routes them to CISA, a technical agency with no content-moderation or criminal-enforcement mandate. Law 116/2025/QH15 routes everything — incident notifications, user-data requests, and content-removal orders — through the same Ministry of Public Security, which is Vietnam's police and state-security apparatus (bocongan.gov.vn). The law requires service providers to hand over user information to the MPS within 24 hours of a written request — three hours in an emergency — and to remove flagged content within 24 hours, or six in urgent cases (Rajah & Tann Asia).
Collapsing technical incident response and political content control into a single police-run pipeline is not a neutral administrative choice. A company deciding whether to disclose a breach quickly now has to weigh that disclosure against exposure to the same ministry's takedown and data-request powers — a chilling effect NIS2 and CIRCIA were structurally designed to avoid by keeping the reporting channel separate from law enforcement. The law's extraterritorial reach compounds this: foreign platforms operating in Vietnam face binding obligations to comply with these same requests, raising the cost of serving the Vietnamese market precisely for firms with the least appetite to hand user data to a security ministry (chinhphu.vn).
The flat 15% investment mandate has a similar flaw: it substitutes a one-size-fits-all budget rule for genuine risk-based prioritization, which means a low-risk Tier 1 system and a strategically critical Tier 5 system face the same spending floor regardless of actual exposure.
A Fixable Design Flaw, Not a Reason to Scrap the Law
Vietnam was right to close the reporting gap that let VNDirect, PVOIL, and Vietnam Post each improvise a response in 2024. But mandatory disclosure only builds trust if the agency receiving it is seen as a technical responder, not a political enforcer. Splitting the incident-reporting and CSIRT function into a distinct technical body — reporting to, but organizationally separate from, the MPS — would let Vietnam keep the speed of NIS2-style reporting without importing its content-policing baggage into every breach notification.