Еконтроль
Back to News

Critical Infrastructure Cyber Protection Shifts to a Risk-Based Model

Critical infrastructure cyber protection shifts to a risk-based model under Resolution No. 1470. Learn what changed for operators from November 20, 2025.

Published July 21, 20268 min read
Critical infrastructure cyber protection shifts to a risk-based model under Cabinet of Ministers Resolution No. 1470

What Changed: The Cabinet Updated Cyber Protection Rules for CIOs

Critical infrastructure cyber protection in Ukraine has officially moved to a risk-based model. By Resolution No. 1470 of November 13, 2025, the Cabinet of Ministers amended Resolution No. 518 of June 19, 2019 and restated the General Requirements for the cyber protection of critical infrastructure objects in a new edition. The document took effect on November 20, 2025.

The core change is simple to state and large in its consequences: operators no longer just work through a static "do this, do that" list; they build protection around cybersecurity risk management. Instead of a one-time bar to clear before an inspection, there's now a continuous cycle of assessment, planning, and review. We broke the mechanism down in detail in a separate guide to the new risk-based cyber protection model; this piece records the event itself and what has already followed it.

For the security team at an industrial or energy site, this isn't a cosmetic tweak. The requirements are rewritten to almost word-for-word mirror the logic of an information security management system under ISO/IEC 27001, and that overlap is what defines how operators should act next.

Three Steps of the Risk-Based Cyber Protection Model

The State Special Communications Service laid out the new model in an official explainer as a simple three-step algorithm. That algorithm is the substance of what changed for a critical infrastructure operator.

  • Assess the current state. The operator evaluates its own cyber protection system and honestly records where it stands right now.
  • Set the targets. Using cybersecurity risk management and a single catalog of measures, the operator defines its target, desired state of protection.
  • Implement the measures. The operator builds a phased plan and records it in a cyber protection plan, which it must review every year and update off-cycle if the risk level changes.

Sound familiar? That's the risk management cycle ISO/IEC 27001 requires of any information security management system. The one difference for now: the resolution makes that cycle mandatory for critical infrastructure operators at the level of the state.

The State Special Communications Service: This Isn't a Formality

Dmytro Pakholchenko, acting director of the State Special Communications Service's Cyber Protection Department, stressed the practical side of the new rules: "These updated requirements are not a mere formality. Compliance will be verified through state control procedures and assessments of the cybersecurity posture of critical infrastructure. Instead of static compliance, the new model encourages a continuous cycle of risk management."

Baseline Measures Stay Mandatory

Moving to the risk-based model doesn't cancel the baseline cyber protection measures. They're mandatory for every operator without exception, regardless of the risk assessment result. The risk-based approach defines what to do on top of that floor, not a replacement for it. The logic "our risk is low, so we can skip the baseline" flatly contradicts the resolution and has already become the most common mistake of the first months.

Who the New Cyber Protection Requirements Apply To

The new model's obligations fall on the critical infrastructure operator, meaning the entity that operates a critical infrastructure object (CIO), and on the owners and administrators of critical information infrastructure objects. The resolution calls them collectively "subjects," and they carry the full weight of the change: assessing the state, maintaining a cyber protection plan, reviewing it annually.

But there's a category of business the General Requirements don't cover, and mixing that up costs time. The resolution explicitly excludes the National Bank, banks, other financial-services-market participants supervised by the NBU, and payment-system operators. A separate document covers the financial sector: National Bank Board Resolution No. 69 of June 27, 2025, "On Critical Infrastructure of the Financial Sector." So the first step for a company is a simple check: which regulator does it answer to, the State Special Communications Service or the NBU?

The Financial Sector Has Its Own Track

Banks, NBU-regulated financial institutions, and payment-system operators fall outside Resolution No. 1470. They're covered by National Bank Board Resolution No. 69 of June 27, 2025, which has its own methodology for identifying financial-sector critical infrastructure objects. Trying to satisfy both documents at once usually just duplicates the work.

Law No. 4336-IX and NIS2: Without the Overstatement

Alongside Resolution No. 1470, people often mention Law No. 4336-IX of March 27, 2025 on the protection of information and cyber protection of state information resources and critical information infrastructure objects. It drops the outdated Complex Information Protection System (KSZI) in favor of risk-management measures maintained throughout a system's lifecycle, and it sets up a national cyber incident response system and mandatory cybersecurity officer positions.

One clarification is worth making up front. This law regularly gets called "the NIS2 law," and that's an overstatement. The State Special Communications Service phrases it more carefully: the law implements specific norms from European cybersecurity directives on incident response, reporting, and risk management. That's a partial alignment of specific practices, not a full transposition of the NIS2 Directive. Bringing Ukraine's regulation into full alignment with NIS2 remains a separate strand of work that isn't finished yet.

NIS2 and Law No. 4336-IX Aren't the Same Thing

Law No. 4336-IX aligns specific norms (incident response, reporting, risk management) with European directives, but it isn't a full transposition of the NIS2 Directive. If an EU partner asks about NIS2 compliance specifically, the blanket line "Ukraine already has NIS2" doesn't cover it.

What Has Already Been Rolled Out Since Adoption

Resolution No. 1470 set the framework, and in the months since adoption the state has filled it with working tools. For an operator, that means there's no longer any excuse to postpone the state assessment: everything needed to start is published.

The State Special Communications Administration updated its Order No. 54 of January 30, 2025 and approved the Catalog of Cyber Protection Measures, the Baseline Measures, and the Methodological Recommendations for applying them. This is the same catalog an operator draws on to pick measures for specific risks when defining its target state.

Separately, the Cabinet of Ministers approved the Procedure for Assessing the State of Cyber Protection by Resolution No. 1799 of December 31, 2025 (in force since January 3, 2026). This is the procedure the state will use to check how well an operator's protection actually works. In other words, the risk-based model right now isn't a declaration for the future; it's a working mechanism with a ready catalog of measures and an approved assessment procedure.

The Main Business Consequence: You Need a Risk-Based ISMS

If you boil Resolution No. 1470 down to one practical takeaway, it's this: a critical infrastructure operator is now required to run a working information security risk management process. And that's the definition of an information security management system (ISMS) under ISO/IEC 27001. The model's three steps map directly onto the standard's structure.

Resolution No. 1470 stepISO/IEC 27001 equivalentWhat it means in practice
Assess the current cyber protection stateRisk assessment (clauses 6.1.2, 8.2)Inventorying assets and vulnerabilities
Catalog of cyber protection measuresAnnex A (list of applicable controls)A reference list of measures against specific risks
Target cyber protection stateStatement of Applicability (SoA)A justified, documented selection of controls
Cyber protection plan with annual reviewRisk treatment plan and the PDCA cyclePhased rollout with periodic review
Cyber protection status assessmentInternal and certification auditIndependent verification that the process works

The difference between the resolution and a certificate isn't in substance; it's in the legal status of the result. The resolution requires you to build and document the process. An ISO/IEC 27001 certificate is independent confirmation from an accredited body that the process really works, not just on paper. So an operator that builds the system around the standard from day one meets the resolution's requirements as a side effect. How certification works, from readiness assessment to audit, is covered in our complete ISO/IEC 27001 guide, and the sector-specific context for developers and SaaS lives on our page for IT companies.

For an operator that already holds a valid certificate, satisfying the resolution mostly comes down to repackaging ready artifacts (a risk register, a Statement of Applicability, a risk treatment plan) into the resolution's terminology. For anyone starting from zero, it's smarter to design the ISMS so it covers both the standard's Annex A and the State Special Communications Service's measures catalog at once. A readiness assessment before certification is the fastest way to see the gap between your current state and the resolution's requirements.

Check Your Readiness for Resolution No. 1470

A free assessment from Bureau Veritas's partner in Ukraine: we'll compare your cyber protection state against Resolution No. 1470's requirements and show you exactly what ISO/IEC 27001 certification would cover.

Learn About ISO/IEC 27001 Certification

FAQ: Critical Infrastructure Cyber Protection

The questions operators ask most often after critical infrastructure cyber protection moved to the risk-based model.

Tags