Decree 211/2025/ND-CP: Civil Cryptography Activities and Import-Export Compliance Notes for ICT Equipment

GOVERNMENT DECREE • CIVIL CRYPTOGRAPHY • ICT

Decree 211/2025/ND-CP: Civil cryptography activities and import-export compliance notes for ICT equipment

Decree 211/2025/ND-CP is a key regulatory instrument for enterprises trading, exporting or importing civil cryptographic products. For ICT devices with encryption, data-security, VPN, token, HSM or cybersecurity functions, the license, conformity and technical dossier should be reviewed before documents are finalized, shipments are booked or customs declarations are filed. This article places the regulation in the practical context of import-export operations, clarifying its scope, affected parties, and the checks required before it is relied on for a shipment dossier. Before implementation, businesses should verify the effective date, amendments, and relevant official guidance applicable to the transaction, while retaining the source and document version used for later explanation or audit.

QUICK SUMMARY

Document

Decree 211/2025/ND-CP of the Government of Viet Nam.

Effective date

Effective from 9 September 2025.

Focus

Business of civil cryptographic products/services; export and import of civil cryptographic products; conformity assessment; amendments to administrative sanctions.

Product groups to review

ICT equipment, network-security devices, encryption devices, data-protection solutions and products with civil cryptographic functions.

Legal note: Whether a device falls under “civil cryptographic product” management cannot be determined only by commercial name or HS code; the actual encryption function, technical documents, firmware/software, use case and appendices of the Decree must be reviewed.

Operational reference material for import-export, logistics, compliance and operations teams. This English version is not an official legal translation.

Illustration for Decree 211/2025/ND-CP: Civil Cryptography Activities and Import-Export Compliance Notes for ICT Equipment
Illustration of the legal document and affected subjects in import-export operations.

DOCUMENT INFORMATION

FieldContent
Document titleDecree on civil cryptography activities and amendments/supplements to Decree 15/2020/ND-CP dated 3 February 2020 on administrative sanctions in postal, telecommunications, radio frequency, information technology and electronic transaction sectors, as amended by Decree 14/2022/ND-CP dated 27 January 2022.
Number211/2025/ND-CP
Issuing authorityGovernment of Viet Nam
Date of issuance25 July 2025
Effective date9 September 2025
Validity statusApplicable from 9 September 2025 according to the Government legal document portal; enterprises should verify validity at the time of each dossier/application.
SignerPham Minh Chinh
ScopeDetailed provisions of the Law on Cyberinformation Security regarding civil cryptography activities and amendments to related administrative-sanction rules.
Applied entitiesEnterprises trading civil cryptographic products/services; exporters/importers of civil cryptographic products; conformity assessment bodies; users, distributors or integrators of products with civil cryptographic functions.

KEY CONTENT TO NOTE

1. Regulatory scope

Article 1 covers the business of civil cryptographic products/services, export/import of civil cryptographic products, conformity assessment and amendments to administrative-sanction provisions. The articles and appendices should be read together.

2. Appendices trigger compliance review

Appendix I concerns the list of civil cryptographic products and services; Appendix II concerns civil cryptographic products subject to export/import licensing. These lists should be reviewed before HS code, product name, model and import dossier are finalized.

3. Export/import license

The export/import license dossier for civil cryptographic products should be prepared before ETA. If technical documents or conformity certificates are not ready, clearance may be delayed and storage/demurrage risks may arise.

4. Sanctions are amended

The Decree amends and supplements certain provisions of Decree 15/2020/ND-CP, as amended by Decree 14/2022/ND-CP. Risk review should cover import, trading, distribution, use and post-clearance documentation.

AFFECTED ENTITIES / PRODUCT GROUPS

Enterprise groupAffected stageDocuments to review
Importer/trading companyPre-import review, customs declaration, post-clearanceReview Appendix II; prepare license, conformity certificate, catalogue, datasheet, encryption-function description, contract, invoice and packing list.
Distributor/brand ownerMarket circulation and B2B distributionCheck whether a civil cryptography business license is required; control labeling, technical materials and record-keeping obligations.
Factory/EPE/FDIImport for internal operation, production or system securityDo not assume internal-use imports are automatically out of scope; use purpose, function and licensing conditions must be checked.
Logistics provider/customs brokerPre-check, declaration support and document coordinationDo not determine technical nature on behalf of the importer, but flag risks for products with encryption, VPN, token, HSM, firewall or data-security functions.

IMPACT ON IMPORT-EXPORT / LOGISTICS OPERATIONS

Operation stagePractical impact
Customs declarationProduct name, HS code, model, serial and function description must match the catalogue/datasheet; avoid generic descriptions such as “network device” where encryption/security functions exist.
DocumentsInvoice, Packing List, B/L/AWB, contract, PO, catalogue, datasheet, C/O, license and conformity documents should refer to the same model/SKU.
TimelinePolicy review should be done before booking or before ETA to avoid storage, demurrage, amendment of declaration or separation of shipment lines.
Post-clearance complianceKeep technical dossier, licenses, certificates, import declarations and distribution data for possible inspection or post-clearance audit.

DOCUMENT CHECKLIST FOR ENTERPRISES

DocumentControl purpose
Catalogue/datasheetIdentify encryption, security, VPN, authentication, key management, key storage or other cryptographic functions.
Model/serial listMatch each model/SKU against the civil cryptographic product lists; avoid grouping different product natures under one generic description.
Civil cryptography business licenseReview if the enterprise trades, distributes, supplies or integrates covered products/services.
Export/import license for civil cryptographic productsReview against Appendix II and licensing procedure at the Government Cipher Committee where the product is covered.
Conformity certificate/declarationReview for imported civil cryptographic products subject to conformity assessment requirements.
Commercial documentsInvoice, Packing List, Sales Contract/PO, B/L/AWB, C/O, transport documents and insurance documents if any.
Post-clearance recordsKeep licenses, certificates, technical dossier, declaration, import documents and appendix-mapping records by shipment/model.

SPECIALIZED TERM NOTES

TermBrief explanation
Civil cryptographyCryptographic techniques, products or services used to protect information outside the state-secret domain.
Civil cryptographic productA product with cryptographic functions for security, authentication, encryption, key management, VPN, data protection or similar functions under the regulated lists.
Conformity certificationAssessment that a product conforms to applicable technical regulations before import, trading or market circulation where required.
ETAEstimated Time of Arrival; a key milestone for counting back the license and dossier preparation timeline.

RELATED LEGAL DOCUMENTS TO REVIEW

Document groupName/No.Issuing authorityEffectivenessRoleArticle/appendix to noteReview note
LawLaw on Cyberinformation Security 86/2015/QH13National AssemblyAccording to the original lawLegal basis for civil cryptographic products/services and cybersecurityArticles 31, 39 and relevant provisionsUse to determine business conditions, conformity assessment and import control.
DecreeDecree 211/2025/ND-CPGovernment9 September 2025Main document analyzedAppendices I, II, III; licensing and sanction provisionsReview product/service lists and products subject to export/import license.
DecreeDecree 15/2020/ND-CPGovernmentAccording to the original and amendmentsAdministrative-sanction decree amended by Decree 211/2025/ND-CPSanction provisions relating to IT, e-transactions and civil cryptographyDo not rely only on the old text without checking amendments.
DecreeDecree 14/2022/ND-CPGovernmentAccording to the original decreeEarlier amendment to Decree 15/2020/ND-CPAmended/supplemented sanction provisionsCompare the layered amendments or use a consolidated version if available.
AppendicesAppendices I, II, III of Decree 211/2025/ND-CPGovernmentAttached to Decree 211/2025/ND-CPLists of products/services, licensed export/import products and dossier formsLists and forms No. 01-08Do not omit appendices when reviewing model, product name and licensing dossier.

VIEW / DOWNLOAD OFFICIAL DOCUMENT

Preferred official source: Government Legal Document Portal, Official Gazette and attached digitally signed PDF.

FULL TEXT OF THE DOCUMENT

SOCIALIST REPUBLIC OF VIET NAM
Independence – Freedom – Happiness

THE GOVERNMENTNo. 211/2025/ND-CP

Decree 211/2025/ND-CP: Civil cryptography activities and import-export compliance notes for ICT equipment

Because the document contains lengthy appendices and dossier forms, the full text is displayed through the official digitally signed PDF preview below to preserve its structure, appendices and legal content.

FULL-TEXT PREVIEW OF DECREE 211/2025/ND-CP

Preferred official source: Government Legal Document Portal and the digitally signed PDF attached there. This preview is intended to display the full text, appendices and forms; enterprises should rely on the official Vietnamese PDF for each actual dossier.

FAQ

1. When does Decree 211/2025/ND-CP take effect?

It takes effect on 9 September 2025. Contracts, dossiers and shipments arising after this date should be reviewed under the new rules and appendices.

2. Which ICT devices need attention?

Devices or software with encryption, VPN, data security, authentication, key management, HSM, firewall, security gateway or network-security functions should be reviewed by actual function and appendix list.

3. Is HS code review enough?

No. HS code is only one customs reference. Product name, model, catalogue, datasheet, firmware/software and use purpose must also be reviewed.

4. When should the export/import license dossier be prepared?

Preferably before booking or, at the latest, before ETA. Waiting until cargo arrival may cause storage, demurrage, document amendment or delivery delay.

5. Does this Decree change duty rates or C/O rules?

It is not a tariff or C/O regulation. However, commodity-policy classification can affect the import dossier, clearance timeline and licensing/conformity obligations.

6. Does internal-use import still need review?

Yes. Intended use is relevant, but it does not replace appendix and function review. Internal use should not be assumed out of scope.

7. What should be retained after clearance?

License, conformity documents, import declaration, commercial documents, catalogue, datasheet, technical dossier and appendix-mapping record by shipment/model.

SOLUTIONS FROM TGIMEX

For ICT products with civil-cryptography elements, the largest risk often arises before transportation: misidentifying commodity policy before arrival. TGIMEX approaches this through dossier control and operational coordination, without replacing the licensing authority or making absolute clearance guarantees.

1. Legal review by model

Read the original instrument, check appendices, identify effective date, affected product groups and trigger conditions based on each model/SKU dossier.

2. Document control

Cross-check Invoice, Packing List, B/L/AWB, Sales Contract/PO, catalogue, datasheet, C/O, license and conformity records to avoid mismatch in product name, model, quantity, origin or technical specifications.

3. Logistics coordination

Build a pre-ETA timeline, identify risk checkpoints, coordinate customs declaration, international transport, trucking, port/warehouse and document remediation.

4. Post-clearance records

Help organize shipment-level records and data for post-clearance audit, inspection and market-circulation obligations where applicable.

Enterprises should review legal requirements before finalizing documents and before ETA to reduce storage, red-channel, supplementary-document and delivery-delay risks.

QUICK CONSULTATION

NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?

Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.

CALL NOW
Zalo
HOTLINE 0963 856 664 / 0982 135 393
EMAIL info@tgimex.com
SUITABLE FOR International shipping · Customs procedures · Import licenses · B2B logistics

Leave a Reply

Discover more from TGIMEX VIETNAM JSC

Subscribe now to keep reading and get access to the full archive.

Continue reading