Circular
Medium
Customs

Consolidated Circular on Safety and Security for Online Banking Services (Circular 50/2024/TT-NHNN as amended by Circular 77/2025/TT-NHNN)

RegHub explainer by New MarketerLast updated:

Based on:Thông tư 50/2024/TT-NHNN; Thông tư 77/2025/TT-NHNN - Government Official Gazette

This explanation was generated by AI and checked by an automated AI review, not by a human expert. It is not legal, tax or accounting advice and may contain errors. Check the official document before you rely on it.

This is a consolidated text issued by the State Bank of Vietnam (SBV/NHNN) merging Circular 50/2024/TT-NHNN dated October 31, 2024 (effective January 1, 2025) with the amendments introduced by Circular 77/2025/TT-NHNN dated December 31, 2025 (effective March 1, 2026). It sets mandatory safety and security requirements for providing online banking services, applying to credit institutions, foreign bank branches, payment intermediary service providers, credit information companies, and (new under the amendment) Mobile Money service providers. Key technical requirements include: information systems must meet security level 3 or higher (level 4 or higher for financial switching and clearing systems) and comply with Vietnamese standard TCVN 11930:2017; network infrastructure must include application and database firewalls plus DoS/DDoS protection; application software must undergo source-code control and testing against the OWASP Top Ten (web) or OWASP Mobile Application Security standard (mobile); Mobile Banking apps must be distributed only through official app stores and must detect and auto-exit when debuggers, emulators, or rooted/jailbroken devices are detected. Transaction confirmation is risk-tiered, combining passwords, PINs, OTPs (SMS/Voice/Soft Token), biometric matching, or e-signatures; payment transactions by organizational customers must separate the creation and approval steps, except for household businesses or micro-enterprises using simplified accounting. A notable new element introduced by Circular 77/2025/TT-NHNN is the «newly established organizational customer» category (entities incorporated or newly onboarded within the past 12 months), which must undergo a risk assessment to determine when biometric or secure e-signature verification applies, with exemptions for state agencies, listed companies, and Fortune Global 500 entities. The new rules under Articles 3 and 10 take effect on a staggered timeline: providers serving both individual and organizational customers must comply from July 1, 2026, while providers serving organizational customers only must comply from October 1, 2026. This is a cybersecurity and technical-standards document for banks and payment intermediaries, outside the tax, accounting, e-invoice, labor, or customs scope that RegHub tracks.

Overview

This document is a consolidated text issued by the State Bank of Vietnam (SBV), merging Circular No. 50/2024/TT-NHNN dated October 31, 2024, on safety and security for the provision of online services in the banking sector (effective January 1, 2025), with the amendments introduced by Circular No. 77/2025/TT-NHNN dated December 31, 2025 (effective March 1, 2026). The consolidated text lets credit institutions and related entities look up the currently effective rules in a single document.

Scope and applicable entities

The Circular governs safety and security requirements for providing online banking services (Online Banking), covering: banking and other business activities of credit institutions and foreign bank branches; payment intermediary services; credit information activities; and (newly added) Mobile Money services. It applies to credit institutions, foreign bank branches, payment intermediary service providers, Mobile Money service providers, and credit information companies (collectively, «units»).

General safety and security principles

Online Banking systems must meet information system security level 3 or higher; systems providing financial switching or electronic clearing services must meet level 4 or higher, and must also comply with Vietnamese standard TCVN 11930:2017. Units must ensure the confidentiality and integrity of customer information and the continuous availability of the system; classify and assess transaction risk by customer group, usage behavior, transaction type, and transaction limits; carry out annual security assessments; and ensure IT infrastructure equipment has clear licensing and provenance.

Technical infrastructure and application software

Network infrastructure must include application firewalls, database firewalls, DoS/DDoS protection, and a security information and event management system; customer information may not be stored in internet-facing zones or the DMZ. Servers must have backup servers, be logically or physically separated from other business systems, and average no more than 80 percent of designed monthly capacity. Online Banking application software must have strict source-code controls and must be tested against the OWASP Top Ten (for web platforms) or OWASP Mobile Application Security standard (for mobile) before going live, must apply end-to-end encryption, must auto-terminate idle sessions, and must separate the creation and approval steps for organizational customers' payment transactions (except for household businesses or micro-enterprises using simplified accounting). Mobile Banking apps specifically must be distributed only through official app stores, undergo a security review at least every three months, and detect and auto-exit when a debugger, emulator, or rooted/jailbroken device is detected.

Electronic transaction confirmation

Transaction confirmation is tiered by risk level and can use one or a combination of methods: passwords (minimum 8 characters, valid up to 12 months), PINs (minimum 6 characters), one-time passwords (SMS OTP, Voice OTP, Soft OTP/Token OTP), biometric matching, or secure e-signatures. For multi-step transactions, confirmation is mandatory at the final approval step.

What changed under Circular 77/2025/TT-NHNN

The amendment introduces the «newly established organizational customer» category - entities incorporated or newly onboarded within the past 12 months - requiring a risk assessment to determine when biometric or secure e-signature verification must apply. Several groups are exempted, including state agencies, public non-business units, credit institutions, listed companies, Fortune Global 500-listed entities, and non-resident foreign investors opening accounts for indirect investment. The amendment also adds Mobile Banking app version-control requirements (security review at least every 3 months, no downgrading allowed) and extends the Circular's scope to Mobile Money services.

Implementation timeline

For the new requirements in Articles 3 and 10, providers serving both individual and organizational customers must comply starting July 1, 2026; providers serving organizational customers only must comply starting October 1, 2026. This is a cybersecurity and information-security document primarily affecting credit institutions, payment intermediaries, and fintech companies - it falls outside the tax, accounting, e-invoice, labor, and customs topics RegHub tracks.

Thông tư 50/2024/TT-NHNN; Thông tư 77/2025/TT-NHNNEffective: January 1, 2025