Dossier for a Cybersecurity Product Business License

Rate this article

What conditions must be met to be granted a License to trade cybersecurity products? Where is the dossier for applying for a License to trade cybersecurity products submitted? What does the dossier include?

1. What conditions must be met to be granted a License to trade cybersecurity products?

Under Clause 1, Article 42 of the Law on Network Information Security 2015 on conditions for licensing cybersecurity product and service business:

Related services

M&A, Equity Transfer and Project Transfer

If you are preparing an equity transfer, M&A transaction, project transfer or restructuring, ANT Legal can help review legal risks and transaction structure.

Website information is for general reference only and does not replace legal advice for a specific matter.

“1. An enterprise is granted a License to trade cybersecurity products and services, except products and services in points a, b, c, d, Clause 1 and point a, Clause 2, Article 41 of this Law, when it meets all of the following conditions:

a) Conforming to the national cybersecurity development strategy, planning and plan;

b) Having a system of equipment and facilities suitable for the scale of providing cybersecurity products and services;

c) Having management, executive and technical personnel meeting professional requirements on information security;

d) Having a suitable business plan.”

Accordingly, to be granted a License to trade cybersecurity products, your enterprise must meet the licensing conditions for cybersecurity product and service business specifically provided by the cybersecurity law.

2. Where is the dossier for applying for a License to trade cybersecurity products submitted? What does the dossier include?

Under Article 43 of the Law on Network Information Security 2015 on dossiers for applying for a License to trade cybersecurity products and services:

“1. An enterprise applying for a License to trade cybersecurity products and services submits its application dossier at the Ministry of Science and Technology.

2. The application dossier for a License to trade cybersecurity products and services is made in five sets, comprising:

a) Application for a License to trade cybersecurity products and services, clearly stating the types of cybersecurity products and services to be traded;

b) Copies of the Enterprise Registration Certificate, Investment Registration Certificate or other documents of equivalent value;

c) Explanatory statement on the technical equipment system ensuring compliance with law;

d) Business plan including scope, target recipients of products and services, product and service standards and quality;

dd) Copies of professional diplomas or certificates on information security of the management, executive and technical personnel.

3. In addition to the documents in Clause 2 of this Article, the dossier for applying for a License to trade cybersecurity inspection and assessment services or information confidentiality services not using civil cryptography must also include:

a) Criminal record certificates of the legal representative and the management, executive and technical personnel;

b) Technical plan;

c) Plan for confidentiality of customer information in the service provision process.”

Accordingly, your enterprise submits the application dossier at the Ministry of Science and Technology. The dossier for applying for a License to trade cybersecurity products is made in five sets with contents specifically provided as stated above.

3. Responsibilities of enterprises trading cybersecurity products

Under Article 46 of the Law on Network Information Security 2015 on responsibilities of enterprises trading cybersecurity products and services:

“1. Manage dossiers and documents on technical solutions and technology of products.

2. Prepare, store and keep confidential customer information.

3. Report annually to the Ministry of Science and Technology on the business, export and import of cybersecurity products and services before December 31.

4. Refuse to provide cybersecurity products and services upon discovering organizations or individuals violating the law on the use of cybersecurity products and services, or violating agreed commitments on the use of products and services provided by the enterprise.

5. Temporarily suspend or cease providing cybersecurity products and services to ensure national defense, national security, social order and safety at the request of competent state agencies.

6. Coordinate and facilitate competent state agencies in implementing professional measures upon request.”

Discuss this matter with ANT Legal M&A, Equity Transfer and Project Transfer