Skip to content
IT Ukraine Association
Eng/Укр
  • About the Association
    • About us
    • Our benefits
    • Events calendar
    • Ambassadors of the Association
    • Annual Reports
    • Testimonials
  • Areas of work
    • IT Industry Development & Advocacy Center
    • IT Ukraine Global
    • Companies Sourcing
  • The Association’s Committees
    • The AgriTech Committee
    • The CyberTech Committee
    • The FinTech Committee
    • The EdTech Committee
    • The AI Committee
  • Projects
  • Research
  • Partners & members
    • IT companies
    • Partners
  • Latest news
    • Association’s news
    • Industry News
    • Blogs
IT Ukraine Association
IT Ukraine Association
Eng / Укр
Eng/Укр
Join ITU
  • About the Association
    • About us
    • Our benefits
    • Events calendar
    • Ambassadors of the Association
    • Annual Reports
    • Testimonials
  • Areas of work
    • IT Industry Development & Advocacy Center
    • IT Ukraine Global
    • Companies Sourcing
  • The Association’s Committees
    • The AgriTech Committee
    • The CyberTech Committee
    • The FinTech Committee
    • The EdTech Committee
    • The AI Committee
  • Projects
  • Research
  • Partners & members
    • IT companies
    • Partners
  • Latest news
    • Association’s news
    • Industry News
    • Blogs
Home
/
Association's News
/
The European Cyber Shield: Ukraine as a Driver for New Cybersecurity Standards

The European Cyber Shield: Ukraine as a Driver for New Cybersecurity Standards

Publication date:

  • 06.11.2025

Publication from:

IT Ukraine

The European Union, in response to the unprecedented cyber-attacks of recent years, is introducing a comprehensive reform in the field of cybersecurity. Ukraine, with its unique practical experience in countering hybrid threats, is becoming a reliable partner for the EU in shaping the new system of digital resilience.

 

The European regulatory package in the field of cyber protection includes three fundamental acts:

  • NIS2 (Network and Information Security Directive) — establishes personal accountability for company management regarding the implementation of cyber risk management measures, control, and staff training;
  • DORA (Digital Operational Resilience Act) — unifies requirements for managing ICT risks and the interaction between financial institutions and IT service providers;
  • Cyber Solidarity Act — creates a joint EU ‘Cyber Shield’ that will ensure rapid response to large-scale incidents.
 

Furthermore, the Cyber Resilience Act (CRA) mandates a ‘secure-by-design’ approach for all digital-element products, from hardware devices to software. Producers must establish a transparent update policy, maintain a Software Bill of Materials (SBOM), and ensure timely remediation of vulnerabilities.

Ukraine is actively harmonising its legislation with European standards. In 2025, key regulatory acts were adopted that strengthened the national cyber protection system:

  • The Law of Ukraine on the Protection of Information and Cybersecurity of State Information Resources;
  • Cabinet of Ministers of Ukraine Resolution No. 367 on security risk management at Category I critical infrastructure facilities;
  • Cabinet of Ministers of Ukraine Resolution No. 712, which introduced security profiles—basic, sectoral, and targeted—to standardise policies and agreements in the field of cyber protection.
 

Moreover, by joining ENISA (the EU Agency for Cybersecurity) and the NATO CCDCOE, Ukraine is now able to engage in international drills and best practice sharing. This marks a further step in its integration into the European digital sphere.

 

Companies Should Take the Following Steps:

  • Approve a cyber-risk policy and train management on the principles of NIS2, DORA, and CRA. This is necessary to meet the requirements for the board’s role (NIS2), mitigate the risk of sanctions, and successfully pass compliance checks by European partners and auditors.
  • Update incident response procedures using the 24–72–30 timeline. This ensures compliance with EU standards, reduces downtime (MTTD/MTTR), and provides ready-made notification templates for clients and regulators, as this directly impacts trust and SLAs (Service Level Agreements).
  • Revise contracts with EU clients (security clauses / DORA clauses). The goal is to ensure contractual compatibility, including an ICT service register, audit and testing rights, sub-outsourcing rules, and incident notification protocols. This is a condition for entering and remaining in the EU market and for preventing penalties or contract termination.
  • Conduct a CRA gap-analysis (secure-by-design, SBOM, CVD, update policy). This is vital to meet the application deadlines (11.09.2026/11.12.2027), avoid market access barriers for products entering the EU, and reduce the cost of last-minute changes in the future.
  • Unify internal policies and public/CI (Critical Infrastructure) contracts according to security profiles (CMU No. 712) and risk management requirements (CMU No. 367). This is to ensure compliance with Ukrainian rules for critical infrastructure and maintain consistent requirements for contractors across the entire supply chain.
 

Ukraine possesses not only the legislative framework but also genuine, real-world experience. Attacks on the energy system (BlackEnergy, 2015), the financial sector (NotPetya, 2017), and government resources (since 2022) have positioned Ukrainian specialists among the world’s best in matters of cyber resilience.

 

The harmonisation of Ukrainian legislation with European acts is not a formality but a step towards building a resilient digital space. Ukraine is not only adapting to EU norms but also sharing its own experience, which is already helping to strengthen Europe’s cyber defence

states Martha Kindrys, Director, IT industry development and advocacy Center, IT Ukraine Association
 

A unified European cyber-defence front is currently taking shape, with Ukraine positioned as a vital contributor. While the shift to NIS2 compliance is a long-term undertaking, it will ultimately result in a secure digital ecosystem where business, state entities, and society function as a cohesive whole.

 

Click here to read the full material

1,618
FacebookXLinkedInTelegramShare

See also:

tg_image_3750095749
IT Ukraine

IT Ukraine Association and Ministry of Digital Transformation Strengthen Dialogue on Cybersecurity and Cloud Technologies

The CyberTech Committee of the IT Ukraine Association met with Vitalii Balashov, Deputy Minister of Digital Transformation of Ukraine. The...

Read more
  • 19.09.2026
site + fb
IT Ukraine

AgriTech Delegation at TechCrunch Disrupt 2026

Five Ukrainian AgriTech companies will showcase their solutions at TechCrunch Disrupt 2026, one of the world’s leading events for startups,...

Read more
  • 17.09.2026
tg_image_1795747910
IT Ukraine

Ukraine as Europe's Technology Partner

Ukraine’s technology potential and the shift from international support to partnership, joint development and investment were key themes of the...

Read more
  • 16.09.2026
698621616
IT Ukraine

INNONEERS, welcome to the IT Ukraine Association!

INNONEERS, a Ukrainian technology company specializing in software engineering, AI solutions, and digital product development for international businesses, has joined...

Read more
  • 14.09.2026
Subscribe to our updates
Contacts

Address: 04071, Kyiv,
str. Yaroslavska, 58 (Astarta
Organic Business Centre)

Phone:+38 099 266 39 03

E-mail:
hello@itukraine.org.ua

Address: 04071, Kyiv, str. Yaroslavska, 58 (Astarta
Organic Business Centre)

Phone:+38 099 266 39 03

E-mail:
hello@itukraine.org.ua

  • Facebook
  • LinkedIn
  • Instagram
  • YouTube
Share to...
BufferCopyEmailFacebookFlipboardHacker NewsLineLinkedInMessengerMixPinterestPrintRedditSMSTelegramTumblrXVKWhatsAppXingYummly