The Ukrainian GovTech sector possesses significant export potential. According to World Bank rankings, Ukraine is recognized as a global leader in digital government services. Domestic solutions have attracted substantive interest from the governments of Estonia, Denmark, and the United Kingdom. However, when attempting to convert this interest into actual contracts, Ukrainian product IT companies encounter an invisible regulatory barrier: the lack of harmonization between national and European cybersecurity requirements.
For company owners, CEOs, and CFOs, this issue extends beyond mere technical compliance. The inability to automatically convert Ukrainian certificates of conformity (specifically KSZI) into international standards (ISO/IEC 27001, SOC 2, or the requirements of the NIS2 directive) creates a situation of double financial and administrative burden. This discrepancy functions as a non-tariff barrier that artificially restricts the capitalization and scaling of Ukrainian technologies in the European market.
The phenomenon of Ukrainian GovTech: From recognition to real contracts
The government sector is among the most conservative software buyers. According to research by Deloitte Ukraine and the Global Government Technology Centre Kyiv, global trends in public procurement are fundamentally shifting: governments no longer purchase technology solely for automation, but instead invest in sustainability, long-term impact, and infrastructure security resilience.
While the high maturity of Ukrainian digital solutions is undisputed, it does not automatically open the doors to European tenders. Local Ukrainian certificates (KSZI) are not recognized during EU procurement processes. This is not a result of intentional discrimination by European institutions; the problem lies in the structural regulatory divergence between the two approaches to information security certification.
Hidden export tax: The financial dimension of double audits
For developers of GovTech solutions, the necessity of maintaining two parallel security circuits becomes a significant financial burden. To simultaneously serve the Ukrainian public sector and European customers, companies are forced to duplicate audit procedures and maintain isolated compliance teams.
This process has direct economic consequences:
- Increased operating expenses (OpEx): The need to undergo isolated audits for internal and external markets can lead to an increase in compliance-related operating costs of up to 53.7%.
- Double capital investments (CapEx): Instead of directing funds toward R&D or scaling in EU markets, businesses are forced to invest significant resources in parallel certification and the services of foreign auditing firms.
- Barrier for small and medium-sized enterprises (SMEs): High initial costs for adapting to the local requirements of the purchasing country make participation in international tenders economically unfeasible for many Ukrainian startups and mid-sized companies.
Anatomy of divergence: Conflict of regulatory philosophies
The fundamental discrepancy lies in the methodology. The Ukrainian KSZI system (based on technical information protection standards) historically relies on fixing the specific state of a system, requiring compliance with a formal list of requirements. Any architectural changes (such as scaling microservices or updating cloud infrastructure) may require re-certification.
International practice, particularly ISO/IEC 27001 and SOC 2, is oriented toward dynamic risk management. Western auditors evaluate a company's ability to continuously identify threats, adapt processes, and minimize risks in real time.
Comparative matrix of regulatory requirements: Ukraine vs. EU
| Comparison criterion | Ukraine: KSZI | EU: ISO/IEC 27001, SOC 2, NIS2 |
|---|---|---|
| Basic security standard | Formal list of requirements and templates. | International standards and directives (dynamic architecture). |
| Risk assessment approach | Static control of fixed configurations. | Dynamic assessment, oriented toward business processes. |
| Mutual recognition of results | Absent for foreign certificates. | Broad recognition of certificates from accredited EU bodies. |
| Control frequency | One-time certification with re-certification required for changes. | Continuous monitoring, annual supervisory audits. |
Impact on time-to-market and technological adaptation tools
The double bureaucratic burden directly affects time-to-market. Delays caused by the need to re-validate security controls for different regulatory environments can postpone releases by up to 27.7%. This reduces the competitiveness of Ukrainian solutions compared to European products that already possess the necessary certifications by default.
To minimize these risks, Ukrainian developers adapt their strategy at the design stage. For instance, Softengi systematically implements international standards, as evidenced by their certification under the ISO/IEC 42001:2023 artificial intelligence management standard. This allows for structuring development according to the requirements of Western regulators from day one.
Another example is the use of ready-made enterprise-level technological platforms instead of developing systems from scratch. ECM/DMS class solutions, such as Megapolis.DocNet, are built on the UnityBase platform (a joint development by companies within the Intecracy Group, an alliance of independent entities linked by partner agreements and share exchanges; key developer — InBase). The use of commercial editions (Enterprise or Defence) of this platform ensures the presence of built-in role-based access control (RBAC/RLS), audit trails, and secure integrations. Incorporating these architectural principles during the development stage significantly facilitates subsequent ISO audits, reducing final CapEx.
The path to standard harmonization
For the full-scale expansion of Ukrainian technologies into the EU, a combined effort between business and the state is required. Industry associations, including the Software Ukraine Association, consistently emphasize the need for systemic harmonization.
The public sector must initiate the process of mutual recognition of cybersecurity certificates and transition to modern risk management frameworks. For their part, IT company leaders should make business decisions to orient toward ISO 27001 architectural requirements at the development stage, utilizing platforms with proven security levels. Only by overcoming this regulatory divergence will the Ukrainian GovTech segment be able to fully establish itself in the global market.
FAQ
Why is the KSZI certificate not accepted during public procurement in EU countries?
The KSZI certificate of conformity is based on national technical information protection standards that are valid exclusively within Ukraine. European government customers require compliance with international security and risk management standards, such as ISO/IEC 27001, SOC 2, or the requirements of the NIS2 directive.
How much does it cost to adapt a Ukrainian GovTech product to ISO 27001 security requirements?
The exact amount varies depending on the scale of the product and its initial architecture. Costs are comprised of auditor fees, consulting, and the need for technical refactoring. Separate audits for internal and external markets can increase compliance-related operating expenses by up to 53.7%.
How can the certification process be simplified when entering the EU market?
The primary business decision is to design the architecture according to international standards from day one or to use enterprise-level platform solutions (e.g., commercial editions of the UnityBase platform) that already feature built-in access control (RBAC/RLS) and audit trail modules. This minimizes the costs of system restructuring before the certification audit.
Data sources
- vertexaisearch.cloud.google.com: Як Україні перетворити GovTech на експортну індустрію - блог - dev.ua
- vertexaisearch.cloud.google.com: Україна серед лідерів GovTech у рейтингу Світового банку
- vertexaisearch.cloud.google.com: Естонія, Данія, Велика Британія цікавляться українським govtech: що саме їм потрібно і чи є тут гроші - 24 Канал
- vertexaisearch.cloud.google.com: GovTech змінюється: уряди більше не купують технології, а інвестують в ефект сталості – дослідження Deloitte Ukraine та Global Government Technology Centre Kyiv