Law / Ukraine

Law on the Basic Principles of Ensuring Cybersecurity, Critical Infrastructure Owner Cyber-Defense and Audit Duty

Закон України "Про основні засади забезпечення кібербезпеки України" № 2163-VIII від 05.10.2017 (редакція від 03.04.2025, підстава -… 4070-IX), ст. 6(4)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 9 May 2018.

A sector security regimes rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This binds an owner or manager of an enterprise, institution or organization that Ukraine's critical-infrastructure designation process (Law No. 1882-IX "On Critical Infrastructure") has classified as a critical infrastructure object; that Law's own sector list (its Article 9(4)) includes, among seventeen sectors, governance and essential public administrative services, energy, water, food, healthcare, the pharmaceutical industry, vaccine manufacturing and biolab operation, information services, electronic communications, financial services, transport, defense and state security, law enforcement, civil protection, space activity, the chemical industry, and research activity.
  • Ensure the cyber-defense of the communication and technological systems of your critical infrastructure object, and protect its technological information, in accordance with legislative requirements.
  • Organize an independent information-security audit of your critical infrastructure object, to the requirements the Cabinet of Ministers of Ukraine sets, or, where you are a bank, another financial-services-market participant the National Bank of Ukraine regulates and supervises, a payment-system operator or participant, or a payment-services technology operator, to the requirements the National Bank of Ukraine sets instead.
  • No fine or criminal penalty currently attaches to a breach of this duty by name: Article 12 only cross-references whatever civil, administrative or criminal liability already exists elsewhere in Ukrainian law for the underlying conduct.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 12 does not itself criminalize a breach of Article 6(4): it is a generic cross-reference under which a person guilty of violating legislation in the fields of national security, electronic communications or information protection, where cyberspace is the place or means of the offense, bears whatever civil, administrative or criminal liability the underlying conduct already carries under other Ukrainian legislation. No provision reviewed here creates a criminal offense specific to a critical infrastructure owner's failure to ensure cyber-defense or to organize the required audit.

Who enforces it

Enforcement body

The Cabinet of Ministers of Ukraine, which forms the cyber-defense requirements and operates the independent information-security-audit system for a critical infrastructure object generally, except for a critical infrastructure object in Ukraine's banking system or non-bank financial-services markets, a payment-system operator or participant, or a payment-services technology operator, where the National Bank of Ukraine performs that function instead.

Settledness

zakon.rada.gov.ua and data.rada.gov.ua both return a site-wide robots.txt disallow for every crawler, so this row is pinned to an archived snapshot because the live host answers every crawler with the same disallow; a fresher snapshot or a registered official channel could resolve the first open question directly.

As of
19 September 2026
Open questions
  • Does Law № 4336-IX, which the document's own status card records as in force from 19 October 2025, change Article 6's critical-infrastructure-owner cyber-defense or independent-audit duties from the 3 April 2025 text pinned here?
  • Has the Cabinet of Ministers of Ukraine published the general cyber-defense requirements and independent information-security-audit rules Article 5(3) and Article 6(2) direct it to set for a critical infrastructure object outside the banking and payment-systems sector?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 6(4) of Law No. 2163-VIII places responsibility for ensuring the cyber-defense of the communication and technological systems of a critical infrastructure object, and for protecting its technological information in accordance with legislative requirements, on the owners and/or managers of the enterprise, institution or organization that object belongs to.

The same sentence places responsibility for organizing an independent information-security audit of that object on the same owners and/or managers. Article 6(1) defers which enterprise, institution or organization counts as a critical infrastructure object, and the Register of Critical Infrastructure Objects that records that designation, to the separate Law No. 1882-IX "On Critical Infrastructure".

Article 6(2) and Article 5(3) split who sets the general cyber-defense requirements and the independent-audit rules an owner must follow: the Cabinet of Ministers of Ukraine for a critical infrastructure object generally, and the National Bank of Ukraine for a bank, another participant in the financial-services markets the National Bank regulates and supervises, a payment-system operator or participant, or a payment-services technology operator.

Article 12 does not set its own fine or custodial penalty for a breach of Article 6(4): it is a generic cross-reference stating that a person guilty of violating legislation in the fields of national security, electronic communications or information protection bears whatever civil, administrative or criminal liability the underlying conduct already carries under other law.

The Law took effect six months after its official publication, under its own final and transitional provisions, and remains in force.

When LexLint raises it

  • operates_essential_service
  • handles_health_records
  • provides_financial_services
  • provides_telecom_services

Read the law

Internet Archive Wayback Machine snapshot (20250419072232) of the official consolidated text, zakon.rada.gov.ua, Law No. 2163-VIII

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived April 19, 2025. Publisher's page: https://zakon.rada.gov.ua/laws/show/2163-19

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app