Circular
Informational

Circular 47/2026/TT-BCA Issuing the National Technical Regulation on Cybersecurity for Electronic Document Storage Information Systems in Party and State Agencies (QCVN 12:2026/BCA)

RegHub explainer by New MarketerLast updated:

Based on:47/2026/TT-BCA - Government Official Gazette

This explanation was generated by AI and checked by an automated AI review, not by a human expert. It is not legal, tax or accounting advice and may contain errors. Check the official document before you rely on it.

On May 12, 2026, the Ministry of Public Security issued Circular 47/2026/TT-BCA promulgating National Technical Regulation QCVN 12:2026/BCA on cybersecurity for electronic document storage information systems. The regulation takes effect July 1, 2026. Its scope is limited to Party and State agencies, covering document storage systems that do not hold state secrets. The regulation sets out detailed technical requirements - risk management, physical security, data backup and recovery, encryption, network monitoring, and incident response - graded across 5 information system security tiers. This is an internal technical standard for government bodies and does not directly apply to private enterprises, household businesses, or individuals, except where a company acts as an IT vendor to these agencies. As a result, it falls outside the tax, accounting, e-invoice, labor, or customs topics RegHub tracks for the SME community.

Document Information

  • Reference number: 47/2026/TT-BCA (promulgating QCVN 12:2026/BCA)
  • Date issued: May 12, 2026
  • Effective date: July 1, 2026
  • Issuing agency: Ministry of Public Security

Scope

The regulation sets requirements for the management, operation, and cybersecurity assurance of electronic document storage information systems in Party and State agencies, applying only to systems that do not hold state-secret information. It does not apply to storage systems containing state secrets, or to security and authentication solutions falling under the fields of cryptography (co yeu) and official digital signatures.

Applicability

Agencies, organizations, and individuals involved in managing, operating, or securing electronic document storage information systems within Party and State bodies.

Key Technical Content

The regulation grades information systems across 5 security tiers and sets 22 groups of corresponding technical requirements, including:

  • Cybersecurity risk and asset management (hardware, software, information), with risk-assessment records retained
  • Physical security of server areas, access control, and activity logging
  • Secure configuration of hardware and software, plus account and access-rights management
  • Vulnerability management; security logs must be encrypted and protected against unauthorized modification
  • Data backup and recovery: at least 3 copies, stored across 2 physically separate locations, with at least 1 copy on non-rewritable, air-gapped storage media
  • Vendor management: storage service providers must host infrastructure inside Vietnam, control remote access, and encrypt data in transit
  • Cybersecurity incident response: incidents must be reported to the competent authority within 24 hours of detection
  • Disaster recovery assurance (BCP/DR plans) and system-wide time synchronization to the UTC standard

Section 3 of the regulation details the assessment methodology (document review, process checks, evidence) for each requirement group to determine a pass or fail rating.

Who Is Affected

The circular binds only Party and State agencies that manage electronic document storage systems, along with the IT and cybersecurity vendors serving them. Private enterprises, household businesses, and individuals are not directly subject to it, unless they act as service providers to these state agencies.

Effective Date

The circular takes effect July 1, 2026. The Director of the Cybersecurity and Hi-tech Crime Prevention Department (Ministry of Public Security) is responsible for monitoring and inspecting implementation.

47/2026/TT-BCAEffective: July 1, 2026