{"id":17759,"date":"2026-06-25T10:06:16","date_gmt":"2026-06-25T07:06:16","guid":{"rendered":"https:\/\/lexcovery.com\/2026\/06\/on-approval-of-the-regulation-on-critical-information-infrastructure-of-the-financial-sector-and-amendments-to-certain-regulatory-legal-acts-of-the-national-bank-of-ukraine-regarding-cyber-protection\/"},"modified":"2026-06-25T10:06:16","modified_gmt":"2026-06-25T07:06:16","slug":"on-approval-of-the-regulation-on-critical-information-infrastructure-of-the-financial-sector-and-amendments-to-certain-regulatory-legal-acts-of-the-national-bank-of-ukraine-regarding-cyber-protection","status":"publish","type":"post","link":"https:\/\/lexcovery.com\/en\/2026\/06\/on-approval-of-the-regulation-on-critical-information-infrastructure-of-the-financial-sector-and-amendments-to-certain-regulatory-legal-acts-of-the-national-bank-of-ukraine-regarding-cyber-protection\/","title":{"rendered":"On Approval of the Regulation on Critical Information Infrastructure of the Financial Sector and Amendments to Certain Regulatory Legal Acts of the National Bank of Ukraine regarding Cyber Protection"},"content":{"rendered":"<p>This NBU Resolution No. 66 is **** (as it relates to the regulation of the financial sector and cybersecurity); it establishes clear rules for the protection of critical information infrastructure (CII) in the financial sector. The document defines the criteria by which banking and non-banking financial institutions must identify their information and communication systems as CII objects. The resolution also obliges critical infrastructure operators to compile a registry of such objects and submit it to the National Bank. The document introduces enhanced cybersecurity measures for these systems and amends existing NBU regulations regarding cybersecurity.<\/p>\n<p>### Structure and Main Provisions<br \/>\nThe resolution consists of a regulatory part and three annexes:<br \/>\n1. **Regulation on CII of the Financial Sector:** defines terminology, criteria for classifying systems as CII, the procedure for maintaining the registry, and cybersecurity requirements for various categories of operators (banks, payment systems, database administrators).<br \/>\n2. **Amendments to Regulation No. 43:** update information protection requirements in the payment market, specifically regarding the classification of cyber incidents and the procedure for reporting them.<br \/>\n3. **Amendments to Regulation No. 178:** adjust the organization of cybersecurity in the banking system, specifically clarifying the composition of information exchange participants and the requirements for external audits for bank CII operators.<\/p>\n<p>Compared to previous versions, these changes systematize the approach to cybersecurity by integrating it with the requirements of the laws &#8220;On Critical Infrastructure&#8221; and &#8220;On Basic Principles of Ensuring Cybersecurity of Ukraine.&#8221;<\/p>\n<p>### Most Important Provisions for Application<br \/>\n*   **CII Criteria:** A system becomes a CII object if its stoppage would lead to a crisis situation and the financial institution has no alternative for its replacement.<br \/>\n*   **Prohibition on Software Usage:** Operators are strictly prohibited from using software and equipment included in the list of prohibited items (specifically those associated with the aggressor state or sanctioned persons).<br \/>\n*   **Reporting:** Operators are required to identify their CII objects within two months after the resolution enters into force and provide information about them to the NBU. Subsequently, the list must be reviewed annually (as of November 1).<br \/>\n*   **Responsible Persons:** Institutions must appoint persons responsible for CII who will ensure data updates and compliance with cybersecurity requirements.<br \/>\n*   **Incident Classification:** Requirements for cyber incident notifications have been updated, including criticality levels (from yellow to black), which requires market participants to provide a rapid response and reporting through the NBU Cyber Defense Center.<\/p>\n<p><a href=\"https:\/\/zakon.rada.gov.ua\/go\/v0066500-26\/ed20260612\"><strong>Full text by link<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This NBU Resolution No. 66 is **** (as it relates to the regulation of the financial sector and cybersecurity); it establishes clear rules for the protection of critical information infrastructure (CII) in the financial sector. The document defines the criteria by which banking and non-banking financial institutions must identify their information and communication systems as&hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"pmpro_default_level":"","footnotes":""},"categories":[15,45],"tags":[],"class_list":["post-17759","post","type-post","status-publish","format-standard","hentry","category-ukrainian-legislation-general-en","category-ukrainian-legislation-important","pmpro-has-access"],"acf":{"patreon-level":0},"_links":{"self":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts\/17759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/comments?post=17759"}],"version-history":[{"count":0,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts\/17759\/revisions"}],"wp:attachment":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/media?parent=17759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/categories?post=17759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/tags?post=17759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}