Skip to content
IT Ukraine Association
Eng/Укр
  • About the Association
    • About us
    • Ambassadors of the Association
    • Our benefits
    • Annual Reports
    • Testimonials
  • Areas of work
    • IT Industry Development & Advocacy Center
    • IT Ukraine Global
  • The Association’s Committees
    • The AgriTech Committee
    • The CyberTech Committee
    • The FinTech Committee
    • The EdTech Committee
    • The AI Committee
  • Є-Support!
  • Partners & members
    • IT companies
    • Partners
  • Latest news
    • Association’s news
    • Industry News
    • Blogs
  • Calendar
IT Ukraine Association
IT Ukraine Association
Eng / Укр
Eng/Укр
Join ITU
  • About the Association
    • About us
    • Ambassadors of the Association
    • Our benefits
    • Annual Reports
    • Testimonials
  • Areas of work
    • IT Industry Development & Advocacy Center
    • IT Ukraine Global
  • The Association’s Committees
    • The AgriTech Committee
    • The CyberTech Committee
    • The FinTech Committee
    • The EdTech Committee
    • The AI Committee
  • Є-Support!
  • Partners & members
    • IT companies
    • Partners
  • Latest news
    • Association’s news
    • Industry News
    • Blogs
  • Calendar
Home
/
Association's News
/
The European Cyber Shield: Ukraine as a Driver for New Cybersecurity Standards

The European Cyber Shield: Ukraine as a Driver for New Cybersecurity Standards

Publication date:

  • 06.11.2025

Publication from:

IT Ukraine

The European Union, in response to the unprecedented cyber-attacks of recent years, is introducing a comprehensive reform in the field of cybersecurity. Ukraine, with its unique practical experience in countering hybrid threats, is becoming a reliable partner for the EU in shaping the new system of digital resilience.

 

The European regulatory package in the field of cyber protection includes three fundamental acts:

  • NIS2 (Network and Information Security Directive) — establishes personal accountability for company management regarding the implementation of cyber risk management measures, control, and staff training;
  • DORA (Digital Operational Resilience Act) — unifies requirements for managing ICT risks and the interaction between financial institutions and IT service providers;
  • Cyber Solidarity Act — creates a joint EU ‘Cyber Shield’ that will ensure rapid response to large-scale incidents.
 

Furthermore, the Cyber Resilience Act (CRA) mandates a ‘secure-by-design’ approach for all digital-element products, from hardware devices to software. Producers must establish a transparent update policy, maintain a Software Bill of Materials (SBOM), and ensure timely remediation of vulnerabilities.

Ukraine is actively harmonising its legislation with European standards. In 2025, key regulatory acts were adopted that strengthened the national cyber protection system:

  • The Law of Ukraine on the Protection of Information and Cybersecurity of State Information Resources;
  • Cabinet of Ministers of Ukraine Resolution No. 367 on security risk management at Category I critical infrastructure facilities;
  • Cabinet of Ministers of Ukraine Resolution No. 712, which introduced security profiles—basic, sectoral, and targeted—to standardise policies and agreements in the field of cyber protection.
 

Moreover, by joining ENISA (the EU Agency for Cybersecurity) and the NATO CCDCOE, Ukraine is now able to engage in international drills and best practice sharing. This marks a further step in its integration into the European digital sphere.

 

Companies Should Take the Following Steps:

  • Approve a cyber-risk policy and train management on the principles of NIS2, DORA, and CRA. This is necessary to meet the requirements for the board’s role (NIS2), mitigate the risk of sanctions, and successfully pass compliance checks by European partners and auditors.
  • Update incident response procedures using the 24–72–30 timeline. This ensures compliance with EU standards, reduces downtime (MTTD/MTTR), and provides ready-made notification templates for clients and regulators, as this directly impacts trust and SLAs (Service Level Agreements).
  • Revise contracts with EU clients (security clauses / DORA clauses). The goal is to ensure contractual compatibility, including an ICT service register, audit and testing rights, sub-outsourcing rules, and incident notification protocols. This is a condition for entering and remaining in the EU market and for preventing penalties or contract termination.
  • Conduct a CRA gap-analysis (secure-by-design, SBOM, CVD, update policy). This is vital to meet the application deadlines (11.09.2026/11.12.2027), avoid market access barriers for products entering the EU, and reduce the cost of last-minute changes in the future.
  • Unify internal policies and public/CI (Critical Infrastructure) contracts according to security profiles (CMU No. 712) and risk management requirements (CMU No. 367). This is to ensure compliance with Ukrainian rules for critical infrastructure and maintain consistent requirements for contractors across the entire supply chain.
 

Ukraine possesses not only the legislative framework but also genuine, real-world experience. Attacks on the energy system (BlackEnergy, 2015), the financial sector (NotPetya, 2017), and government resources (since 2022) have positioned Ukrainian specialists among the world’s best in matters of cyber resilience.

 

The harmonisation of Ukrainian legislation with European acts is not a formality but a step towards building a resilient digital space. Ukraine is not only adapting to EU norms but also sharing its own experience, which is already helping to strengthen Europe’s cyber defence

states Martha Kindrys, Director, IT industry development and advocacy Center, IT Ukraine Association
 

A unified European cyber-defence front is currently taking shape, with Ukraine positioned as a vital contributor. While the shift to NIS2 compliance is a long-term undertaking, it will ultimately result in a secure digital ecosystem where business, state entities, and society function as a cohesive whole.

 

Click here to read the full material

1,263
FacebookXLinkedInTelegramShare

See also:

TechStep англ
IT Ukraine

TechStep Sweden: Ukrainian delegation at Vitalis 2026

Four Ukrainian companies — KNOPKA UKRAINE, InDevLab, Progalit, and LifesaverSIM — explored Sweden’s healthtech ecosystem during Vitalis 2026 in Gothenburg...

Read more
  • 12.05.2026
social (1)
IT Ukraine

Obriy AI, welcome to the IT Ukraine Association!

Obriy AI, the team behind SURE — an enterprise-grade multi-agent GenAI platform and AI solutions for businesses and enterprises —...

Read more
  • 11.05.2026
telegram-cloud-photo-size-2-5424962467504264897-y
IT Ukraine

Acropolium, welcome to the IT Ukraine Association!

Acropolium — an international IT company with over 20 years of experience in software development, is now part of the...

Read more
  • 29.04.2026
fb (1)
IT Ukraine

IT Ukraine Association unveils “The Code Economy” — A Comprehensive Study on the Impact of IT Across the Country's Industries

Information technology has already become a systemic foundation of Ukraine’s economy. This is evidenced by “The Code Economy” — the...

Read more
  • 24.04.2026
Subscribe to our updates
Contacts

Address: 04071, Kyiv,
str. Yaroslavska, 58 (Astarta
Organic Business Centre)

Phone:+38 099 266 39 03

E-mail:
hello@itukraine.org.ua

Address: 04071, Kyiv, str. Yaroslavska, 58 (Astarta
Organic Business Centre)

Phone:+38 099 266 39 03

E-mail:
hello@itukraine.org.ua

  • Facebook
  • LinkedIn
  • Instagram
  • YouTube
Share to...
BufferCopyEmailFacebookFlipboardHacker NewsLineLinkedInMessengerMixPinterestPrintRedditSMSTelegramTumblrXVKWhatsAppXingYummly