{"id":17771,"date":"2026-06-25T10:11:21","date_gmt":"2026-06-25T07:11:21","guid":{"rendered":"https:\/\/lexcovery.com\/2026\/06\/on-the-approval-of-the-procedure-for-monitoring-the-activities-of-the-national-cyber-incident-cyberattack-and-cyberthreat-response-team-cert-ua-and-sectoral-and-regional-cyber-incident-cyberattac\/"},"modified":"2026-06-25T10:11:21","modified_gmt":"2026-06-25T07:11:21","slug":"on-the-approval-of-the-procedure-for-monitoring-the-activities-of-the-national-cyber-incident-cyberattack-and-cyberthreat-response-team-cert-ua-and-sectoral-and-regional-cyber-incident-cyberattac","status":"publish","type":"post","link":"https:\/\/lexcovery.com\/en\/2026\/06\/on-the-approval-of-the-procedure-for-monitoring-the-activities-of-the-national-cyber-incident-cyberattack-and-cyberthreat-response-team-cert-ua-and-sectoral-and-regional-cyber-incident-cyberattac\/","title":{"rendered":"On the Approval of the Procedure for Monitoring the Activities of the National Cyber Incident, Cyberattack, and Cyberthreat Response Team (CERT-UA) and Sectoral and Regional Cyber Incident, Cyberattack, and Cyberthreat Response Teams (CSIRT)"},"content":{"rendered":"<p>This Order of the State Service of Special Communications and Information Protection (SSSCIP) approves the mechanism for monitoring the capabilities of Computer Emergency Response Teams (CERT-UA and CSIRTs). The document establishes clear rules for assessing whether these teams meet the prescribed technical and organizational requirements. The primary goal is to ensure an appropriate level of cyber defense through regular monitoring, self-assessment, and external auditing. In the event of non-compliance, teams are required to remediate the violations; otherwise, they may lose the right to perform delegated tasks.<\/p>\n<p>**Structure and Main Provisions:**<br \/>\nThe Order consists of six sections describing various forms of monitoring:<br \/>\n1. **Self-assessment:** conducted by the team independently at least once a year.<br \/>\n2. **Peer review:** conducted once every three years among teams to which the tasks of the national team have been delegated.<br \/>\n3. **Assessment by SSSCIP:** carried out both for the national team (once every three years) and for sectoral\/regional teams (within the first year after the delegation of tasks).<br \/>\n4. **Analysis of results and remediation of violations:** defines the procedure for responding to identified non-compliances.<br \/>\nCompared to previous approaches, this Procedure details the &#8220;delegation&#8221; process and introduces clear maturity criteria based on Order No. 87 dated 03.02.2026.<\/p>\n<p>**Important Provisions for Implementation:**<br \/>\n*   **Assessment Methods:** Monitoring is carried out by verifying compliance with the parameters defined in the Requirements for Organizational and Technical Capability.<br \/>\n*   **External Audit:** Teams have the right to engage accredited conformity assessment bodies to fulfill the requirements regarding self-assessment or peer review.<br \/>\n*   **Legal Consequences:** If a team fails to remediate identified violations within a three-month period, SSSCIP has the right to terminate the delegation of tasks and exclude such a team from the corresponding Registry.<br \/>\n*   **Reporting:** The results of any assessment must be formalized in a report, which is signed by the head of the team and retained for three years.<\/p>\n<p><a href=\"https:\/\/zakon.rada.gov.ua\/go\/z0757-26\/ed20260514\"><strong>Full text by link<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This Order of the State Service of Special Communications and Information Protection (SSSCIP) approves the mechanism for monitoring the capabilities of Computer Emergency Response Teams (CERT-UA and CSIRTs). The document establishes clear rules for assessing whether these teams meet the prescribed technical and organizational requirements. The primary goal is to ensure an appropriate level of&hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"pmpro_default_level":"","footnotes":""},"categories":[15,45],"tags":[],"class_list":["post-17771","post","type-post","status-publish","format-standard","hentry","category-ukrainian-legislation-general-en","category-ukrainian-legislation-important","pmpro-has-access"],"acf":{"patreon-level":0},"_links":{"self":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts\/17771","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/comments?post=17771"}],"version-history":[{"count":0,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts\/17771\/revisions"}],"wp:attachment":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/media?parent=17771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/categories?post=17771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/tags?post=17771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}