ICS security authorization under Resolution No. 712: full transition support

Resolution No. 712 of the Cabinet of Ministers of Ukraine of 18.06.2025 changes the very model of confirming the security of information and communication systems (ICS) that process state information resources or restricted information whose protection is required by law. The familiar cycle of «building a CIPS — state examination — certificate of compliance» is being replaced by ICS security authorization: a risk-based approach founded on target security profiles, assessment of conformity with these target security profiles and inclusion of the system in the register of authorized systems. For institutions and enterprises this is not a change of terminology but a restructuring of information-protection processes — with new requirements for documentation, technical tools and how the work is organised.

NVP «Plasmotekhnika» supports the transition as a full cycle: from an audit of the current state of the ICS and formation of a target security profile to assessment, support of authorization and inclusion of the system in the register of authorized systems. We combine the competencies of a systems integrator in the field of restricted-information protection with those of a manufacturer of its own certified protection tools, so we cover both the organisational and technical parts of the transition without engaging additional contractors.

What changes: from CIPS to ICS security authorization

The CIPS (comprehensive information-protection system) model has for decades been the main mechanism for confirming the security of state information systems. The protection system was built according to regulatory documents in the field of technical information security, and its compliance was confirmed by a state examination. This approach ensured control but had well-known limitations: the requirements were largely generic and poorly accounted for the specifics of a particular system and current threats, while the certificate effectively fixed the configuration at the moment of examination — significant changes to the ICS entailed repeated procedures.

ICS security authorization under Resolution No. 712 is implemented differently. A target security profile is defined for the system — a set of protection requirements matching the type of system, the nature of the information processed and the level of risk. A conformity assessment of the system against the requirements of the target security profile is then carried out; based on its results, an authorization decision is taken and the system is included in the register of authorized ICS. The key difference is continuity: compliance with the security requirements is maintained throughout the entire lifecycle of the system rather than being «fixed» by a one-off act.

CriterionBefore: CIPSNow: ICS security authorization
Basic approachMeeting generic requirements of TPI regulatory documentsRisk-based: requirements set by the target security profile of the specific system
Conformity confirmationState examination of the CIPS, certificate of complianceAssessment of conformity with the profile and an authorization decision
System statusCertificate for a fixed configurationInclusion in the register of authorized ICS
Response to system changesSignificant changes — re-examinationAdjustment of the target security profile where necessary, compliance maintained over the entire lifecycle, change management
Timelines & transitional provisionsSet by regulation; the specific timelines for each system are determined by its owner (holder), but at least once a year

If your institution already operates a certified CIPS, it does not mean the work has to start from scratch: a significant part of the implemented measures and documentation is reused when bringing the system into line with the developed target security profile. The order of recognising valid confirmations and the transitional provisions are defined by regulatory documents — the specific conditions for your system are clarified during the initial consultation.

What it means for your institution: risks and benefits

Non-compliance with the new model is not an abstract «irregularity» but concrete consequences for the institution and its management:

  • Legitimacy of information processing. Without confirmed compliance with the security requirements, processing restricted information in the system becomes legally vulnerable — from findings during inspections to the suspension of business processes that depend on this system.
  • Integrations and data exchange. A system that has not passed security authorization and is not included in the register risks losing the ability to interact with state registers and exchange data with other systems.
  • Management responsibility. The state of information protection is the personal responsibility of the head of the institution and the officials responsible for information protection. Non-compliance with the security requirements is recorded by inspections and carries administrative consequences.
  • Real cybersecurity risks. Protection that exists only «on paper» under the old model does not match current threats. The transition is an opportunity to align technical protection not only with the requirements but with the real attack landscape.

A transition started in good time brings additional benefits: planned budgets and timelines instead of last-minute «inspection-driven» work; the chance to combine bringing the system into compliance with modernising IT infrastructure and security protection tools; readiness for regulators’ requests; and, for businesses working with the public sector, the confirmed status of an authorized system as a competitive advantage.

How we support the transition: four stages

We run the transition project from the first survey to inclusion of the system in the register of authorized systems. The client gets one accountable team and a clear plan of work instead of a set of disparate services.

Stage 1. Audit and target security profile

We survey the ICS: inventory assets, flows of restricted information, the existing CIPS or implemented protective measures. We determine which requirements the system falls under and form the target security profile. The result of the stage is a gap analysis: a list of discrepancies between the current state and the profile requirements, with an estimate of the scope of work and priorities. It is at this stage that the client receives a justified plan and budget for the transition.

Stage 2. Bringing into compliance and preparing for assessment

We eliminate the identified discrepancies. The organisational part — policies, regulations, allocation of roles and responsibilities, system documentation. The technical part — implementation or modernisation of protection tools: from technical information security tools to cyber-defence solutions. Where certified TPI tools are needed, we apply our own products with State Service of Special Communications expert conclusions — with no dependence on third-party suppliers. We prepare the full set of documents for assessment.

Stage 3. Conformity assessment

We support the client throughout the procedure of assessing the system’s conformity with the requirements of the target security profile: interaction with the assessing party, prompt resolution of findings, refinement of documentation and settings. The goal of the stage is to pass the assessment on the first attempt, without repeated iterations that stretch the timeline.

Stage 4. Authorization and inclusion in the register

We prepare the materials for the authorization decision and support the process of including the ICS in the register of authorized systems. After authorization we help maintain the system’s compliance throughout its lifecycle: monitoring, periodic security control, change management — so that the authorized-system status is not lost after the very first modernisation.

Why Plasmotekhnika: a manufacturer, not just an integrator

Most participants in the compliance-support market are consulting companies or multi-vendor resellers. Our difference is that we are simultaneously a full-cycle systems integrator in information protection and a manufacturer of our own certified TPI tools. This has practical significance for authorization projects:

  • Own TPI tools with State Service of Special Communications expert conclusions (conclusion numbers — [TBC]): the secure workstations PLASMA-ZV-ARM/MONO with passive protection against leakage via technical channels and PLASMA-ZARM/AZ with active protection, plus the PLASMA DD data diode — a one-way security gateway for connecting networks of different levels. The technical part of the profile requirements is covered by products we are responsible for as the manufacturer.
  • TPI licences and permits. Work is carried out under current licences; document details are provided on the «Licences & expert conclusions» page.
  • The full cycle in one pair of hands. Audit, design, implementation, certification, instrumental control — all TPI, cyber-defence and IT-infrastructure work is done by one team, without handing responsibility between contractors.
  • Public-sector experience. We work with government bodies and enterprises and understand both the regulator’s formal requirements and the real operational constraints of institutions.

Frequently asked questions about Resolution No. 712 authorization

Who is ICS security authorization mandatory for?

Primarily for government bodies, enterprises, institutions and organisations whose systems process restricted information or information whose protection is required by law. The exact list of systems subject to the requirements is defined by regulatory documents. Whether this applies to your specific system is clarified at the audit stage; a brief description of the system and the categories of information processed is enough for this.

How does authorization differ from CIPS?

CIPS is the construction of a protection system according to generic regulatory requirements, confirmed by state examination and a certificate for a fixed configuration. Authorization is a risk-based model: requirements are formed by a target security profile for the specific system, compliance is confirmed by assessment, and status by inclusion in the register of authorized ICS. The main practical difference is that compliance is maintained continuously throughout the system’s lifecycle, including change management.

How long does the transition take?

The duration depends on the scale of the system, the state of the existing CIPS or protective measures and the volume of discrepancies with the target profile. Regulatory timelines for individual procedures are [TBC]. We provide a realistic schedule for your system based on the audit results: after the gap analysis, timelines stop being an assumption and become a plan of work.

Where do we start the transition?

With an audit. The first step is inventorying the systems that process restricted information, assessing the current state of protection and a gap analysis against the target security profile requirements. This gives a justified plan and budget before the main work starts — and lets you make decisions on facts rather than assumptions. You can order an audit via the request form at the bottom of the page.

We have a certified CIPS. Do we need to redo everything?

No — an existing CIPS is an asset, not a lost investment. A significant part of the implemented measures, protection tools and documentation is reused when bringing the system into line with the target profile. The order of recognising valid confirmations and the transitional provisions are defined by regulatory documents — [TBC]. In practice the question is resolved like this: the gap analysis shows what is credited and what needs refinement, and this very list becomes the plan of work.

What documents need to be prepared?

An indicative set: organisational and administrative documents on information protection (policies, orders, allocation of responsibility), a description of the ICS and its boundaries, risk-assessment results, documentation on the implemented protection tools — including expert conclusions on TPI tools — and materials for the conformity-assessment procedure. The exact list depends on the target security profile of the specific system; we form and support the set of documents together with the client at the preparation stage.

Start with an assessment of your system

The transition to ICS security authorization is a managed project with clear stages, not a spontaneous reaction to an inspection. The earlier the audit is carried out and the target security profile formed, the more room there is to plan the budget and timelines. Leave a request via the request form — we will hold an initial consultation, assess the state of your system and propose a transition plan. Phone: +38 (044) 204-83-62, NVP «Plasmotekhnika», 03056, Kyiv, vul. Politekhnichna 16, office 021.

Need a consultation or a technical brief?

Leave a request — a specialist engineer will get in touch within one business day.

By submitting the request, you agree to the privacy policy.