Ukrainian telecom software providers aiming to scale their business in the European Union are increasingly facing a severe economic barrier—the so-called "invisible tariff." This complex set of regulatory requirements often consumes a significant portion of a project's total budget, sometimes exceeding the cost of development itself. For owners, CEOs, and CFOs of domestic BSS/OSS developers, this creates a difficult dilemma: allocate a substantial share of the budget to compliance and architectural security at the design stage, or face a months-long delay in time-to-market due to certification deadlocks.
As highlighted in integration challenge analyses (such as materials from WinnerLex and the IT Ukraine Association), regulatory compliance in the EU is no longer a post-release formality. Today, it is a defining factor for system integration, maintaining export margins, and protecting IP capitalization. Conformity assessment procedures and telecom software adaptation must be integrated into the development lifecycle from day one.
The invisible tariff: why EU regulatory compliance is a critical barrier
Exporting telecom software to the EU was traditionally evaluated through the lens of technological competitiveness. However, reality dictates different rules: the fragmentation of the European regulatory landscape has become a key obstacle to expansion. While EU-wide directives exist, local requirements can vary, forcing vendors to adapt their products to the specifics of individual markets.
This "invisible tariff" consists of costs related to audits, modifying the system core to ensure data sovereignty, and restructuring architecture to meet strict security standards. If architects and CFOs do not incorporate these processes into the roadmap in advance, the company risks losing contracts with European operators who are prohibited from deploying uncertified software into their critical networks.
The NIS2 architectural challenge: how cyber-resilience requirements change BSS/OSS logic
The NIS2 directive is fundamentally changing the rules of the game for digital infrastructure developers. Telecom operators in the EU are classified as essential entities. Consequently, third-party software integrated into their environments—billing, routing, or subscriber management systems (BSS/OSS)—automatically falls under strict oversight.
According to the ENISA Threat Landscape 2025 report, essential entities under the NIS2 directive were involved in 53.7% of all registered security incidents. Furthermore, digital infrastructure and services account for approximately 27.7% of data breaches. These figures clearly explain why European regulators insist on detailed Supply Chain Security from operators.
For a Ukrainian BSS/OSS developer, this means an inevitable architectural overhaul. The product must support extended logging, Zero Trust authentication models, data encryption, and the technical capability to generate incident reports promptly.
The double certification trap: local requirements and European CE marking
Although Ukrainian legislation in the field of electronic communications is being actively updated to harmonize with market surveillance requirements—a critical step for cross-border compatibility—a gap remains between local procedures and European standards. Ukrainian companies often face a double regulatory burden: the need to meet domestic security requirements while simultaneously undergoing complex European conformity assessment procedures.
The European market requires specific conformity assessment procedures, including CE marking for hardware-software complexes. Attempts to complete these procedures "externally" after development is finished usually result in the discovery of architectural non-conformities. Refactoring the system core at this stage can delay product deployment by several months.
Architectural solutions for maintaining export margins
Delaying the release of a finished telecom product due to a lack of certificates means frozen capital and direct financial losses. To avoid this, companies use mature platform-based or highly specialized solutions whose architecture is already adapted to high requirements.
For example, within the solution portfolio of the Intecracy Group—an alliance of independent companies linked by partner agreements and share exchanges—the DooxSwitch VoIP platform handles switching and billing tasks while meeting modern reliability standards. It integrates softswitch and real-time charging, ensuring accurate and secure processing of Call Detail Records (CDR) and voice traffic routing.
When there is a need to develop custom enterprise solutions or internal document management and control systems (building complex BSS/OSS portals or client registries), the low-code platform UnityBase serves as a reliable technological foundation (a joint development by Intecracy Group companies, where InBase is a key, but not sole, developer). For high-load projects and systems with heightened security requirements, official documentation recommends the Enterprise or Defence commercial editions. These allow for the implementation of necessary compliance functions at the platform level: Role-Based Access Control (RBAC/RLS), deep audit trails, Domain metadata for generating secure APIs, and strict authentication. Using a ready-made architectural base reduces the risk of discovering non-conformities during the final stages of certification.
Strategy for minimizing barriers: the Shift-Left Compliance approach
To transform regulatory barriers into a competitive advantage, Ukrainian vendors should integrate compliance control into the early stages of the product lifecycle.
- Regulatory audit during the Discovery phase: Clear identification of target EU countries and the specific requirements of their regulators in the field of electronic communications and data protection.
- Security by Design: Integration of NIS2 requirements (encryption, auditing, access control) directly into the system's base architecture.
- Supply Chain Security (SBOM): Ensuring full transparency regarding used open-source components and third-party libraries, which is a mandatory requirement during conformity assessment.
Compliance matrix for telecom software against key EU requirements
| EU regulator requirement | Technical implementation in BSS/OSS architecture | Impact on business metrics |
|---|---|---|
| NIS2 requirement for cyber incidents | Automatic security event logging (audit trail), supply chain monitoring. | Prevention of penalties under the directive. |
| Data localization and sovereignty | Storing subscriber personal data and CDRs within EU infrastructure, access segmentation. | Critical condition for admission to contracts with European telecom operators. |
| Conformity Assessment | Completing procedures for EU market surveillance, providing a Software Bill of Materials (SBOM). | Minimization of time-to-market delays; shortened sales cycles. |
Despite strict regulatory requirements, systematic compliance is a path to sustainable growth in the EU market. The advantage goes to developers who implement security and data sovereignty requirements as an integral part of their engineering culture, rather than as a formal obstacle.
FAQ
What are the main requirements of the NIS2 directive for Ukrainian BSS/OSS developers?
The NIS2 directive requires the implementation of strict Supply Chain Security, the technical ability to promptly generate incident reports, and the use of access control models (such as Zero Trust) and data encryption to protect the digital infrastructure of essential entities (telecom operators).
How long does telecom software certification in the EU take, and how does it affect the project?
The gap between local Ukrainian certifications and EU conformity assessment procedures can delay product deployment by several months if these requirements were not accounted for during the architectural design stage.
How can one avoid double certification when exporting software from Ukraine to Europe?
It is recommended to apply a Shift-Left Compliance approach: focus on European standards (such as CE marking and NIS2) from the very beginning of development, conduct EU market surveillance audits during the Discovery phase, and use mature architectural platforms for reliable transaction auditing and access control.
Data sources
- ENISA Threat Landscape 2025
- vertexaisearch.cloud.google.com: Ukrainian Business Integration into the EU: Moving from “Success Stories” to Rigorous Compliance - WinnerLex
- vertexaisearch.cloud.google.com: Ukraine on the Digital Path to the EU: Integration Challenges
- vertexaisearch.cloud.google.com: Ukraine Electronic Communications Regulation 2025 Update