In short
Ahead of Vietnam's 2026 copyright enforcement peak (Decree 341/2025, effective 15 Feb 2026), businesses need a structured software asset audit. A 6-step SAM readiness checklist aligned to ISO/IEC 19770-1:2017.
Why "buying more licences" isn't enough — you need a process
Most Vietnamese businesses react to copyright-enforcement news the same way: call a reseller, buy a few licences, breathe out. That patches a hole; it isn't risk management. When an inter-agency inspection team arrives, what they reconcile is evidence — how many copies of each program you run, how many you licensed legally, and where the receipts are. Without an inventory process running continuously, that number drifts every time an employee installs something new, and you're never truly "clean".
Legally the exposure is clear: under Article 22(1) of Vietnam's Intellectual Property Law, "a computer program is protected as a literary work, whether expressed in source code or object code." So every unlicensed install is an act of reproducing a work without the copyright owner's authorisation — sanctioned by Article 16 of Decree 341/2025/ND-CP (issued 26 Dec 2025, effective 15 Feb 2026, replacing Decree 131/2013).
The systematic answer is what the world calls Software Asset Management (SAM). The international standard ISO/IEC 19770-1:2017 defines an IT asset management system with process groups covering the control environment, planning, inventory, verification & compliance, operations and life-cycle. This article distils that into six practical steps for Vietnamese SMEs.
- Buying licences fixes a moment; SAM keeps you compliant continuously.
- Evidence beats good intentions: inspectors reconcile running copies against receipted licences.
- Legal basis: IP Law Art. 22 (software = a work) → Decree 341/2025 Art. 16 (unauthorised reproduction).
The 2026 context: why this year is different
Two changes make 2026 pivotal. First, on 5 May 2026 the Prime Minister issued Official Telegram 38/CĐ-TTg, launching a nationwide peak IP-enforcement campaign with coordinated operations from 7–30 May 2026. Second, Decree 341/2025/ND-CP — the first full overhaul in eight years, replacing Decree 131/2013 — took effect on 15 February 2026 and runs to 4 chapters, 65 articles.
The most notable enforcement change: Decree 341/2025 expands remedial measures from 4 to 29, and calibrates fines against three criteria: illegal profit obtained, damage caused to the rights holder, or the value of the infringing goods. Statutory maximum fines are unchanged — VND 250 million for individuals, VND 500 million for organisations (Article 5(1): for the same act, the fine on an organisation is double that on an individual).
This article deliberately does not rehash the penalty tables (Dzo has a dedicated post on Decree 341). The point here is simpler: when sanctions get heavier and remedies broader, what protects a business is not luck — it's a compliance file prepared in advance.
- Official Telegram 38/CĐ-TTg (5 May 2026) — nationwide IP peak campaign, 7–30 May 2026.
- Decree 341/2025 effective 15 Feb 2026, replaces Decree 131/2013, 4 chapters / 65 articles.
- Remedial measures: 4 → 29; fines set by 3 criteria (illegal profit / damage / value of infringing goods).
- Fine caps: individuals VND 250m · organisations VND 500m (org = 2× individual, Art. 5(1)).
| Instrument | Relevant content | Sanction / milestone |
|---|---|---|
| Official Telegram 38/CĐ-TTg | Launches a nationwide peak campaign against intellectual-property infringement. | Issued 5 May 2026; coordinated operations 7–30 May 2026. |
| Decree 341/2025/ND-CP | Administrative sanctions for copyright and related rights; replaces Decree 131/2013 (4 chapters, 65 articles). Article 16: unauthorised reproduction of a work. | Effective 15 Feb 2026. Remedial measures expanded 4 → 29. Fine caps: individuals VND 250m · organisations VND 500m (org 2× individual, Art. 5(1)). |
| Intellectual Property Law — Article 22 | Clause 1: a computer program is protected as a literary work, whether expressed in source code or object code. | Basis for treating each unlicensed install as unauthorised reproduction of a work. |
| Decree 131/2013/ND-CP | Prior instrument on administrative sanctions for copyright and related rights. | Replaced by Decree 341/2025 (after 8 years). |
| Fine ceilings (Decree 341/2025, Art. 5(1)) | Fines calibrated against three criteria: illegal profit obtained, damage caused to the rights holder, or value of the infringing goods. | Individuals up to VND 250 million · organisations up to VND 500 million (org = 2× individual). |
A 6-step audit-readiness checklist (aligned to ISO/IEC 19770-1:2017)
The framework below maps ISO/IEC 19770-1:2017 process groups onto six steps you can run today without expensive tooling. The goal: move from "we don't know what we're running" to "a current, owned, periodically-reviewed licence reconciliation."
- Step 1 — Inventory: Scan every workstation/server and list all installed software: name, version, install date, source. This is ISO 19770-1's inventory process group — without this data, every later step is guesswork.
- Step 2 — Gather entitlements: Collect all licence proof: VAT e-invoices, activation emails, vendor contracts/EAs, the accompanying T&Cs. A licence with no valid invoice ≈ no licence at reconciliation time.
- Step 3 — Reconcile & find the gap: Put "copies running" (Step 1) next to "valid entitlements" (Step 2). Flag each program as compliant, under-licensed, or over-licensed (wasted spend).
- Step 4 — Prioritise & remediate the right way: Tackle high-risk software first (design, engineering, office). Buy top-ups through authorised resellers with proper invoices, or migrate to subscription/cloud/open-source where suitable. Never "buy" via channels that can't issue a valid VAT invoice.
- Step 5 — Policy & control: Ban self-installs, restrict local admin rights, and set an approval workflow for new software. ISO 19770-1 stresses controls over duplication/distribution and an audit trail — this is where you stop recurrence.
- Step 6 — Verify periodically: Re-inventory every 6 months (quarterly for larger firms). Compliance is not a one-time state; joiners, leavers, new machines and new software constantly create fresh gaps.
| Step | What to do | Evidence to have |
|---|---|---|
| Step 1 — Inventory | Scan every workstation/server and list all installed software: name, version, install date, source. | List of running software (name · version · install date · source). |
| Step 2 — Gather entitlements | Collect all licence proof accompanying each program. | VAT e-invoices, activation emails, vendor contracts/EAs, accompanying T&Cs. |
| Step 3 — Reconcile & find the gap | Put "copies running" (Step 1) next to "valid entitlements" (Step 2). | Per-program reconciliation: compliant · under-licensed · over-licensed. |
| Step 4 — Prioritise & remediate | Tackle high-risk software first (design, engineering, office); buy top-ups through authorised resellers or migrate to subscription/cloud/open-source. | Proper VAT invoices from authorised resellers (never channels that can't issue a valid VAT invoice). |
| Step 5 — Policy & control | Ban self-installs, restrict local admin rights, set an approval workflow for new software. | Written policy, restricted-admin configuration, audit trail. |
| Step 6 — Verify periodically | Re-inventory every 6 months (quarterly for larger firms). | Periodic review schedule and inventory minutes each cycle. |
When inspectors arrive: do's and don'ts
If you've done the six steps, the inspection is mostly presenting a file rather than panicking. Inter-agency teams typically include specialist inspectors, economic-crime police and authorised software-vendor representatives, with authority to record the state of your machines.
Ground rules: cooperate, hand over the exact file you prepared, and nominate a single point of contact (usually IT/legal). Do not uninstall/install software on the spot, and do not provide false information. If unsure of your rights and obligations, ask to consult a lawyer before signing the minutes — that is a lawful right.
- DO: nominate one contact; present the prepared inventory + licence evidence (Steps 1–2).
- DO: ensure the minutes reflect the true state; ask to consult a lawyer before signing if needed.
- DON'T: uninstall/install software in front of the team to "fix" things.
- DON'T: misreport or hide machines — it can be an aggravating factor.
A note on comparing software vendors
While remediating, businesses often weigh switching vendors (office suites, design tools, cloud solutions). Comparing is legitimate and sensible — but must rest on accurate facts: published prices, licence terms, real features. Spreading false claims to discredit a vendor can breach unfair-competition rules under Vietnam's Competition Law 2018. Dzo's write-ups always weigh pros and cons on verifiable facts, never disparagement.
- Comparing vendors is legitimate — but only on accurate facts (price, terms, real features).
- Disparaging or spreading false claims about a competitor can breach the Competition Law 2018.
Conclusion: a process is cheaper than the risk
The 2026 enforcement peak will be followed by others; Decree 341/2025's penalty framework is here to stay. You can't control the inspection schedule, but you control your own readiness. A six-step SAM process, run every six months, turns "audit" from a dreaded event into an administrative routine. Maintaining it always costs less than the VND 500 million organisational fine ceiling — let alone reputational damage and business disruption.
*This article is for reference only and does not constitute legal advice. Please consult the primary legal texts (cov.gov.vn, chinhphu.vn) or a qualified lawyer before making decisions.*
Sources
- Introduction to Decree 341/2025/ND-CP — Copyright Office of Vietnam (cov.gov.vn)
- Decree 341/2025/ND-CP — luatvietnam.vn
- Decree 341/2025/ND-CP — vanban.chinhphu.vn (official text)
- Vietnam Issues New Decree on Administrative Sanctions for Copyright — Tilleke & Gibbins
- Vietnam's new copyright decree enhances digital & cross-border enforcement — Rouse
- ISO/IEC 19770-1 — ITAM Standards (SAM standard reference)
- Software asset management — Wikipedia (SAM & audit context)
Need a software compliance review?
DZO experts provide a free compliance roadmap within 24 hours — e-VAT invoice, local implementation.
Book a free consultation




