Country

Vietnam Introduces IP Camera Cybersecurity Rules

Back

On May 14, 2026, Vietnam’s Ministry of Public Security (MPS) issued Circular No. 48/2026/TT-BCA, promulgating QCVN 11:2026/BCA, the new National Technical Regulation establishing baseline cybersecurity requirements for surveillance cameras using Internet Protocol (IP). The regulation introduces a new legal framework for IP camera cybersecurity applicable to devices manufactured, imported, and circulated in the Vietnamese market. The Circular enters into force on July 1, 2026, replacing the previous cybersecurity regulation QCVN 135:2024/BTTTT, which was issued by the former Ministry of Information and Communications (MIC).

For manufacturers, importers, and compliance teams, this Regulatory Update introduces new cybersecurity obligations together with a risk-based conformity assessment approach that will determine the applicable certification pathway.

QCVN 11:2026/BCA Establishes Baseline IP Camera Cybersecurity Requirements

The new regulation defines 11 groups of baseline cybersecurity requirements for surveillance cameras using Internet Protocol.

Among the principal requirements are:

Unique password initialization

Devices must use passwords that are unique for each device or require users to establish their own credentials during initialization. Additionally, authentication mechanisms must be designed to prevent brute-force attacks.

Vulnerability management

Manufacturers are required to publish a vulnerability disclosure policy that includes contact information for reporting vulnerabilities as well as timelines for acknowledging reports and providing status updates throughout the remediation process.

Secure update management

The regulation requires devices to support secure software update mechanisms. Moreover, manufacturers must publish the support period applicable to each camera model.

Secure communications

Communication channels must implement cryptographic methods that follow recognized best practices to protect the confidentiality and integrity of communications.

User data protection

Manufacturers must clearly describe the purpose for collecting, processing, and storing personal data. Furthermore, devices must support user consent for personal data processing and provide mechanisms allowing users to withdraw that consent.

Data residency

IP cameras must provide configuration options enabling users to store data within Vietnam.

Interface security

Unused network interfaces, logical interfaces, and debug interfaces must be disabled to reduce potential cybersecurity risks.

These requirements form the baseline framework for IP camera cybersecurity under the new national technical regulation.

Conformity Assessment Depends on Product Risk Level

QCVN 11:2026/BCA introduces a risk-based conformity assessment framework. The applicable conformity assessment procedure depends on whether an IP camera is classified as a medium-risk or high-risk product under a separate draft list issued by the Ministry of Public Security.

For medium-risk products, manufacturers may perform self-assessment based on test reports issued by designated or recognized laboratories.

However, high-risk products require mandatory certification by a conformity assessment body designated by the Ministry of Public Security before demonstrating compliance with the applicable national technical regulation.

The Circular also specifies that conformity assessment requirements will apply once the Ministry publishes the official list of medium- and high-risk products under its management.

Testing Organizations

The Ministry of Public Security has previously designated testing organizations for compliance with the former QCVN 135:2024/BTTTT standard, including:

However, at the time of publication, no testing organizations have yet been officially designated for QCVN 11:2026/BCA.

What This Means for Manufacturers and Importers

Manufacturers and importers of IP surveillance cameras should prepare for the transition to the new regulatory framework before the Circular takes effect on July 1, 2026.

In addition to complying with the new baseline cybersecurity requirements, organizations should determine whether their products will fall within the medium- or high-risk categories once the Ministry of Public Security finalizes the corresponding product list. This classification will determine whether self-assessment or mandatory certification will be required for market access.

The regulation also represents a change in regulatory authority, transferring the applicable cybersecurity technical regulation for IP cameras from the Ministry of Information and Communications to the Ministry of Public Security.

How Entirety Can Help

Organizations monitoring evolving cybersecurity and product compliance requirements across global markets can benefit from Entirety’s Global Regulatory Updates Service, which provides timely intelligence on regulatory developments affecting ICT products and market access.

https://entirety.biz/services/global-regulatoryupdates/

Impact Assessment

Technical Standards? ✅ Yes

Type Approval & Market Access? ✅ Yes

Imports, Customs, Trade, or Market Surveillance? ✅ Yes

Spectrum Management? ❌ No


Sources & Documents

Related articles

Vietnam Cybersecurity Law: Regulatory Updates News

July 28, 2026

Country

Brazil Hazardous Substances Framework Adopted

July 17, 2026

Country

Brazil: RoHS Framework Sets Mandatory Requirements

July 15, 2026

Country
View All