Vietnam has announced plans to build a cybersecurity firewall. The statement was made by Minister of Public Security Lương Tam Quangon February 7, after the conclusion of the 14th National Congress of the Communist Party of Vietnam. It was the first time a senior official has explicitly used the term “cybersecurity firewall” to describe the country’s direction in digital governance.
See also: How AI reduces or amplifies errors in cybersecurity

Although Vietnam has long been internationally regarded as operating one of the most tightly controlled online environments, authorities had not previously declared an intention to build what they now describe as a national cybersecurity firewall.
The announcement coincides with sweeping reforms to the country’s cybersecurity legislation. On December 10, 2025, the 15th National Assembly passed a new Cybersecurity Law that will come into effect on July 1, 2026. It was drafted by the Ministry of Public Security (MPS) and replaces both the Cybersecurity Law of 2018 and the Information Security Law of 2015.
The 2025 Cybersecurity Law introduces new language into Vietnam’s digital governance architecture. Significantly, Point d, Paragraph 2, Article 10 states that authorities will “study the development of a national firewall system.” This is the first time such terminology has appeared in Vietnamese legislation, formally incorporating the concept of a cybersecurity firewall into legislation.
The inclusion of this provision represents a structural change in the way cybersecurity law is framed in the country, elevating the technical filtering and monitoring infrastructure to the level of national policy goals, as reported by The Vietnamese Magazine.
About two months after the law was passed, the Ministry of Public Security released a draft regulation for public comment titled “National Technical Standard for Cybersecurity—Firewall—Basic Technical Requirements.” The document provides information on the proposed technical architecture of the cybersecurity firewall.
See also: United Kingdom strengthens Government Cybersecurity

According to the draft, firewall systems that meet national standards will be mandatory infrastructure for monitoring and filtering online activity. These devices will be capable of filtering traffic and conducting deep packet inspection (DPI). The proposal also includes SSL/TLS inspection capabilities. SSL/TLS protocols—indicated by the “https” prefix in web addresses—are commonly used to encrypt communications between users and websites.
According to the draft framework, firewall systems will be able to decrypt encrypted communications, inspect their content, and then re-encrypt them before forwarding the data.
In addition, the draft calls for the integration of user identity data into personalized control policies. Web filtering mechanisms will be based on blacklists containing at least 100,000 domain names. These blacklists are defined as collections of IP addresses, domains, and URLs that are subject to restriction based on information security policies, with the aim of blocking content or activity that is considered “unwanted.”.
In addition to filtering capabilities, the proposed cybersecurity firewall would require network devices to log detailed information about each user session. The logged data would include time stamps, source and destination addresses, protocols used, and system responses.
User activity will be assessed and assigned a “risk level.” If set limits are exceeded, automated checks or alerts will be triggered and transmitted to cybersecurity authorities.
This risk-based monitoring model adds another layer to the country’s digital governance structure, combining surveillance mechanisms with automated enforcement tools. Separate regulations implementing the Cybersecurity Act of 2025 will further require telecommunications and internet service providers to retain IP address identification data linked to subscriber information for at least 12 months.
See also: Palo Alto: Cyberattacks are facilitated by basic cybersecurity failures
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Companies will also be required to establish direct technical connections that allow the transfer of IP data to the Ministry’s specialized cybersecurity force. Under the proposed rules, user information must be provided within 24 hours of a request, or within three hours in urgent cases. All user data will be stored domestically in the MPS National Data Center.
