In 2026, cybersecurity compliance has become critical for business. According to the ENISA Threat Landscape 2025 report, over 53% of organizations affected by cyberattacks are critical entities. Ukrainian companies operating in the European market must simultaneously comply with the European NIS2 directive, obtain ISO/IEC 27001 certification, and implement national KSZI standards.
Market implications
For Ukrainian businesses, failing to align these standards risks exclusion from the European market and severe regulatory penalties under NIS2. Conversely, successful integration allows companies to avoid duplicating resources, secure their supply chains, and gain a competitive advantage by demonstrating robust, certified security compliance to international partners.
The difference between regulatory requirements
To build an effective security system, it is crucial to understand the distinct nature of these three key standards:
- NIS2: A mandatory EU directive for critical sectors that focuses on management accountability, supply chain security, and rapid incident reporting within 24 and 72 hours.
- ISO/IEC 27001: An international standard for establishing information security management processes, which requires additional gap analysis to achieve full NIS2 compliance.
- KSZI: The Ukrainian regulatory framework aimed at the technical certification of specific information systems, rather than flexible risk management.
Cross-mapping based on NIST CSF 2.0
To avoid duplicating resources, organizations can use a single methodological framework: the NIST Cybersecurity Framework (CSF) 2.0. It helps map and compare the requirements of different standards. Specifically, the Govern function integrates cyber risks into overall corporate governance, while the Respond function helps set up incident response processes in line with the strict time limits of NIS2.
Technical implementation and architectural security
Effective compliance requires implementing Security by Design principles at the software level. As a technological foundation, developers from Intecracy Group use the UnityBase platform. Its commercial editions support access control lists (ACL), row-level security (RLS), and immutable event auditing.
Built on this platform, the Megapolis.DocNet document management system holds a G2-level KSZI certificate, while the DealsSign system is used for external document management. This approach addresses technical security requirements directly at the platform level.
What to do: Five steps to prepare your company
- Gap analysis: Assessing the compliance of ISO 27001 processes with NIS2 and KSZI requirements.
- Risk synchronization: Creating a unified threat registry using the NIST CSF 2.0 methodology.
- Supplier audit: Evaluating vulnerabilities of third parties and contractors.
- Zero Trust implementation: Setting up multi-factor authentication (MFA) and network segmentation.
- Continuous monitoring: Collecting event logs in SIEM systems for rapid response.
Prepared by a Software Ukraine member. Original publication.