Decree 341/2026/ND-CP: Important Changes to Licensing Requirements for Network Products
- Tron Chan

- 1 hour ago
- 5 min read

On September 1, 2026, the Government issued Decree 341/2026/ND-CP on civil cryptography activities (MMDS), which took effect immediately upon issuance. Many HS codes and exemption mechanisms remain unchanged compared with Decree 211/2025/ND-CP.
Key changes under Decree 341/2026/ND-CP
Compared with the previous decree, the key changes include:
Dual-use products incorporating both cyber security and civil cryptography features will be licensed by the Ministry of Public Security, following consultation with the Government Cipher Committee.
Civil cryptography products must undergo conformity testing and certification before being placed on the market.
Dual-Use Products
For dual-use products that incorporate both civil cryptography and cyber security features, Decree 341/2026/ND-CP clearly provides:
The Ministry of Public Security shall issue licenses for the trading of cybersecurity products and services for dual-use products that have both civil cryptography features and cybersecurity features. Before issuing the license, the Ministry of Public Security shall obtain written comments from the Government Cipher Committee regarding the civil cryptography features.
The affected groups of civil cryptography products include:
Product Group | Detailed Description | HS Code |
Network Data Exchange Security Products | Products with functions for encrypting/decrypting and digitally signing/authenticating data transmitted and received over networks, in the form of security hardware or software, which are not classified as IP traffic flow security products (excluding products that have both civil cryptography and cybersecurity features). | 8471.30.90, 8471.41.90, 8471.49.908517.62.42, 8517.62.43, 8517.62.49 |
IP Traffic Flow Security Products | Products with functions for encrypting/decrypting and digitally signing/authenticating data transmitted and received over networks, in the form of security hardware or software, using secure virtual private network technologies, including IPsec VPN, TLS VPN, MACsec and products with similar functions (excluding products that have both civil cryptography and cybersecurity features). | 8471.30.90, 8471.41.90, 8471.49.908517.62.42, 8517.62.43, 8517.62.49 |
Therefore, routers, switches, SD-WAN products, firewalls, etc., that incorporate both civil cryptography and cyber security features will be licensed by the Ministry of Public Security.
For civil cryptography products that do not fall under the dual-use category with cyber security features, licensing is carried out under the civil cryptography licensing mechanism administered by the Government Cipher Committee, where the product falls within the licensing scope of Decree 341.
Definition of Cybersecurity Products
Under the definition of cybersecurity products in Decree 332/2026/ND-CP, the following products are included:
1. Cybersecurity Testing and Assessment Products are hardware and software devices with functions, or designed to integrate functions, for scanning, checking and analyzing the configuration, status and log data of information systems and electronic devices; detecting vulnerabilities and weaknesses; and providing cybersecurity risk assessments.
2. Cybersecurity Monitoring Products are hardware and software devices with functions, or designed to integrate functions, for monitoring and analyzing data, network addresses and network traffic; collecting and analyzing log data in real time; and detecting and issuing alerts regarding abnormal events that may pose cybersecurity risks.
3. Attack and Intrusion Prevention Products are hardware and software devices with functions, or designed to integrate functions, for preventing attacks and intrusions into information systems.
4. Other Cybersecurity Products include the following:
a) Information Collection Concealment Products, including hardware and software devices with functions for covertly collecting information in cyberspace and from electronic devices and equipment;
b) Network Information Suppression Products, including specialized hardware and software devices used to block, inject, interfere with, or disrupt wireless Internet transmission in protected areas or at protected targets; c) Digital Forensics and Investigation Products, including specialized hardware and software devices used to collect, extract, recover and analyze electronic data and conduct digital forensic examinations from electronic data sources;
d) Network System Suppression Products, including specialized hardware and software devices used to suppress or modify the operation of telecommunications networks, Internet networks, computer networks, information systems, information processing and control systems, databases and electronic devices;
dd) IP Address Hiding Products, which are products that establish a network connection between a device and cyberspace through a remote server in order to conceal the device's actual IP address in cyberspace.
Network Products That May Fall Within Cyber security Product Categories
Routers, switches, SD-WAN products, firewalls, etc. may be considered cybersecurity products if they fall into one of the following categories:
Product | Category | Cybersecurity Function | HS Code |
Network Access Control (NAC) | 3 | Cybersecurity monitoring | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
Network-based Firewall | 4 | Attack and intrusion prevention | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
Intrusion Prevention / Detection System (IPS/IDS) | 5 | Attack and intrusion prevention; cybersecurity monitoring | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
DDoS Prevention Product | 6 | Attack and intrusion prevention | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
IoT Security Product | 7 | Attack and intrusion prevention; cybersecurity monitoring; cybersecurity testing and assessment | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
Network Monitoring Product | 10 | Cybersecurity monitoring | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
Virtual Private Network (VPN) / IP Address Hiding Product | 11 | Attack and intrusion prevention over network connections | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
Web Application Firewall (WAF) | 12 | Attack and intrusion prevention | 8471.30.90, 8471.41.90, 8471.49.908517.62.43 |
Other Products | 25 | Attack and intrusion prevention; cyber security monitoring; cyber security testing and assessment; network information suppression; network system suppression | 8471.30.90, 8471.41.90, 8471.49.908517.62.43, 8517.62.49 |
Decree 332/2026/ND-CP lists product group names and the corresponding cybersecurity functions in Appendix I. However, the Decree does not provide separate technical definitions for commercial terms such as “Network Access Control.”
Illustrative Example
The Nokia 7750 routing product (commercial name: Nokia 7750 Service Router) and Nokia 7450 switching product (commercial name: Nokia 7450 Ethernet Service Switch) include the following functions in their product descriptions:
Layer 7 Stateful Firewall
IP security (IPsec)
Next-generation firewall protection, including the ability to detect and control data flows based on L7 application types; operators can configure L7 rules, such as rate limiting for peer-to-peer traffic or blocking certain HTTP(S) domains.

The product documentation also describes integrated services supported by the Nokia ISA platform, including Application Assurance, Layer 7 Stateful Firewall, L2TP Network Server (LNS), Carrier Grade NAT (CG-NAT), IPsec, IP tunneling, IPv4 reassembly, Wireless LAN Gateway (WLGW), Virtualized Residential Gateway (vRGW), and advanced video functionality.
Other security-related functions described for the product include
Syslog events and Threshold Crossing Alerts (TCAs), together with a full set of firewall-related statistics. The Nokia Network Services Platform (NSP) provides graphical reporting for these statistics.
Denial-of-Service (DoS) protection capable of detecting malformed packets, fragmented-packet attacks and volumetric attacks.
Stateful detection of abnormal TCP behavior (TCP misbehavior).

HS Code Assumption
For the purpose of this example, it is assumed that the product will be imported under HS Code 8517.62.43 for routers. The HS Code may differ in an actual import transaction depending on the specific configuration and SKU.
HS Code 8517.62.43 appears in both the regulatory categories relating to civil cryptography and cybersecurity. However, the specific licensing obligations depend on the technical characteristics of the product and the applicable regulatory circumstances.
The IPsec features, together with the firewall functions, attack detection/prevention capabilities and DoS protection described above, provide a strong basis for considering the product as a dual-use product incorporating both civil cryptography and cybersecurity features.
If the specific product is determined to fall within this category, the licensing of the export or import of the cybersecurity product will fall under the authority of the Ministry of Public Security, under the mechanism applicable to dual-use products.
Conclusion
Today, building a network system based on the Zero Trust principle has become increasingly common.
Under this principle, every component of a network or information system may potentially be exposed to cyberattacks, including individual network devices.
As a result, network equipment manufacturers are increasingly integrating more defensive cybersecurity functions into network devices such as routers and switches in order to improve their resistance to cyberattacks.
This trend makes the functional boundary between traditional network infrastructure equipment and cybersecurity products increasingly difficult to determine.
Therefore, understanding the applicable regulations and accurately identifying the functions of a product are critical to ensuring that all required licenses are obtained before importing the product into Vietnam and to avoiding difficulties during customs clearance.

Comments