Law / Ukraine

Law on the Basic Principles of Ensuring Cybersecurity, CERT-UA Incident Notification Duty

Закон України "Про основні засади забезпечення кібербезпеки України" № 2163-VIII від 05.10.2017 (редакція від 03.04.2025, підстава -… 4070-IX), ст. 6(4)-(5), ст. 9(2)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 9 May 2018.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds the same critical-infrastructure-object owner or manager described on this jurisdiction's companion cyber-defense-and-audit row.
  • Inform CERT-UA immediately (невідкладно, without delay; the statute states no fixed hour clock) of a cybersecurity incident affecting your critical infrastructure object's communication or technological systems.
  • Where the incident information you exchange with CERT-UA or another party contains personal data, handle that exchange under the requirements of the Law on the Protection of Personal Data.
  • No fine or criminal penalty currently attaches to a breach of this notification duty by name: Article 12 only cross-references whatever civil, administrative or criminal liability already exists elsewhere in Ukrainian law for the underlying conduct.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 12 does not itself criminalize a failure to notify CERT-UA: it is a generic cross-reference under which a person guilty of violating legislation in the fields of national security, electronic communications or information protection, where cyberspace is the place or means of the offense, bears whatever civil, administrative or criminal liability the underlying conduct already carries under other Ukrainian legislation. No provision reviewed here creates a criminal offense specific to a failure to notify CERT-UA of a cybersecurity incident.

Who enforces it

Enforcement body

The State Service of Special Communications and Information Protection of Ukraine (Держспецзв'язку), which ensures the functioning of CERT-UA.

Settledness

zakon.rada.gov.ua and data.rada.gov.ua both return a site-wide robots.txt disallow for every crawler, so this row is pinned to an archived snapshot because the live host answers every crawler with the same disallow; a fresher snapshot or a registered official channel could resolve the first open question directly.

As of
19 September 2026
Open questions
  • Does Law № 4336-IX, which the document's own status card records as in force from 19 October 2025, change Article 6's CERT-UA incident-notification duty from the 3 April 2025 text pinned here?
  • Has the Cabinet of Ministers of Ukraine, CERT-UA, or the State Service of Special Communications and Information Protection of Ukraine published a specific notification clock or format narrower than the statute's own bare "without delay" standard for a critical-infrastructure owner's Article 6(4) duty to inform CERT-UA?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The same Article 6(4) sentence that places the cyber-defense and audit duties on a critical infrastructure owner also places responsibility for immediately informing CERT-UA, Ukraine's governmental Computer Emergency Response Team, of a cybersecurity incident on the owners and/or managers of the enterprise, institution or organization the affected object belongs to.

Article 6(5) requires that an exchange of cybersecurity-incident information containing personal data comply with the Law on the Protection of Personal Data. Article 9(2) assigns operation of CERT-UA to the State Service of Special Communications and Information Protection of Ukraine.

Article 9(1) lists CERT-UA's own tasks, including maintaining the state register of cyber incidents and giving practical assistance to an owner of a cyber-defense object on preventing, detecting and remedying a cyber incident's consequences. The statute sets no fixed numeric notification clock: it requires the owner or manager to inform CERT-UA "невідкладно" (immediately, without delay), rather than within a stated number of hours.

Article 12 does not set its own fine or custodial penalty for a breach of this notification duty: it is the same generic cross-reference described on this jurisdiction's companion cyber-defense-and-audit row.

When LexLint raises it

  • operates_essential_service
  • handles_health_records
  • provides_financial_services
  • provides_telecom_services

Read the law

Internet Archive Wayback Machine snapshot (20250419072232) of the official consolidated text, zakon.rada.gov.ua, Law No. 2163-VIII

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived April 19, 2025. Publisher's page: https://zakon.rada.gov.ua/laws/show/2163-19

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app