On May 14, 2026, Vietnam’s Ministry of Public Security (MPS) issued Circular No. 48/2026/TT-BCA, promulgating QCVN 11:2026/BCA, the new National Technical Regulation establishing baseline cybersecurity requirements for surveillance cameras using Internet Protocol (IP). The regulation introduces a new legal framework for IP camera cybersecurity applicable to devices manufactured, imported, and circulated in the Vietnamese market. The Circular enters into force on July 1, 2026, replacing the previous cybersecurity regulation QCVN 135:2024/BTTTT, which was issued by the former Ministry of Information and Communications (MIC).
For manufacturers, importers, and compliance teams, this Regulatory Update introduces new cybersecurity obligations together with a risk-based conformity assessment approach that will determine the applicable certification pathway.
QCVN 11:2026/BCA Establishes Baseline IP Camera Cybersecurity Requirements
The new regulation defines 11 groups of baseline cybersecurity requirements for surveillance cameras using Internet Protocol.
Among the principal requirements are:
Unique password initialization
Devices must use passwords that are unique for each device or require users to establish their own credentials during initialization. Additionally, authentication mechanisms must be designed to prevent brute-force attacks.
Vulnerability management
Manufacturers are required to publish a vulnerability disclosure policy that includes contact information for reporting vulnerabilities as well as timelines for acknowledging reports and providing status updates throughout the remediation process.
Secure update management
The regulation requires devices to support secure software update mechanisms. Moreover, manufacturers must publish the support period applicable to each camera model.
Secure communications
Communication channels must implement cryptographic methods that follow recognized best practices to protect the confidentiality and integrity of communications.
User data protection
Manufacturers must clearly describe the purpose for collecting, processing, and storing personal data. Furthermore, devices must support user consent for personal data processing and provide mechanisms allowing users to withdraw that consent.
Data residency
IP cameras must provide configuration options enabling users to store data within Vietnam.
Interface security
Unused network interfaces, logical interfaces, and debug interfaces must be disabled to reduce potential cybersecurity risks.
These requirements form the baseline framework for IP camera cybersecurity under the new national technical regulation.
Conformity Assessment Depends on Product Risk Level
QCVN 11:2026/BCA introduces a risk-based conformity assessment framework. The applicable conformity assessment procedure depends on whether an IP camera is classified as a medium-risk or high-risk product under a separate draft list issued by the Ministry of Public Security.
For medium-risk products, manufacturers may perform self-assessment based on test reports issued by designated or recognized laboratories.
However, high-risk products require mandatory certification by a conformity assessment body designated by the Ministry of Public Security before demonstrating compliance with the applicable national technical regulation.
The Circular also specifies that conformity assessment requirements will apply once the Ministry publishes the official list of medium- and high-risk products under its management.
Testing Organizations
The Ministry of Public Security has previously designated testing organizations for compliance with the former QCVN 135:2024/BTTTT standard, including:
- PSI Testing and Certification Joint Stock Company
- Center for Standards and Quality Application
- Center for Telecommunications Quality Measurement
However, at the time of publication, no testing organizations have yet been officially designated for QCVN 11:2026/BCA.
What This Means for Manufacturers and Importers
Manufacturers and importers of IP surveillance cameras should prepare for the transition to the new regulatory framework before the Circular takes effect on July 1, 2026.
In addition to complying with the new baseline cybersecurity requirements, organizations should determine whether their products will fall within the medium- or high-risk categories once the Ministry of Public Security finalizes the corresponding product list. This classification will determine whether self-assessment or mandatory certification will be required for market access.
The regulation also represents a change in regulatory authority, transferring the applicable cybersecurity technical regulation for IP cameras from the Ministry of Information and Communications to the Ministry of Public Security.
How Entirety Can Help
Organizations monitoring evolving cybersecurity and product compliance requirements across global markets can benefit from Entirety’s Global Regulatory Updates Service, which provides timely intelligence on regulatory developments affecting ICT products and market access.
https://entirety.biz/services/global-regulatoryupdates/
Impact Assessment
Technical Standards? Yes
Type Approval & Market Access? Yes
Imports, Customs, Trade, or Market Surveillance? Yes
Spectrum Management? No