Ukraine's private-sector cybersecurity posture rests on one currently enacted critical-infrastructure-owner duty, filed here in two provision-scoped rows, plus a second, broader physical-and-cyber resilience statute named but not filed, and an EU-accession NIS2-alignment reform track this review could not confirm has produced a text.
The Law "On the Basic Principles of Ensuring Cybersecurity of Ukraine" (Закон України "Про основні засади забезпечення кібербезпеки України"), Law No. 2163-VIII of 5 October 2017, took effect six months after its official publication under its own final provisions, commonly dated 9 May 2018, and remains in force.
Its Article 6(4) places responsibility for the cyber-defense of a critical infrastructure object's communication and technological systems, for the protection of technological information, for immediately informing Ukraine's governmental Computer Emergency Response Team (CERT-UA) of a cybersecurity incident, and for organizing an independent information-security audit of the object, on the owners and/or managers of the enterprise, institution or organization the object belongs to.
Article 6(1) defers the designation of a critical infrastructure object, and the Register of Critical Infrastructure Objects itself, to a separate statute, the Law "On Critical Infrastructure" (Закон України "Про критичну інфраструктуру"), Law No. 1882-IX of 16 November 2021, in force six months after its own publication under its own final provisions.
That Law's Article 9(4) sector list of protected "vital functions and services" names, among seventeen sectors, governance and essential public administrative services, energy, water, food, healthcare, the pharmaceutical industry, vaccine manufacturing, information services, electronic communications, financial services, transport, defense and state security, law enforcement, civil protection, space activity, the chemical industry, and research.
Law No. 1882-IX's own Article 21 separately binds a designated critical-infrastructure operator to a further duty, naming cybersecurity as one strand of an integrated physical-security, operational-systems-security and cybersecurity protection obligation, together with a general, not cyber-specific, duty to inform the national critical-infrastructure-protection system's sectoral and functional bodies of an incident at the object and to file an annual compliance report; because that duty is bundled into a single physical-and-cyber resilience mandate rather than separable into this topic's four registered law families, and because its own final and transitional provisions (paragraph 11) still task the future Authorized Body with drafting the administrative and criminal sanctions for a violation of it within one year of that body's start of operations, it is named here rather than filed as its own instrument, the treatment this jurisdiction's own companion German row gives the CER Directive's physical-resilience KRITIS-Dachgesetz.
Neither Law No. 2163-VIII's Article 6(4) nor Law No. 1882-IX's Article 21 currently carries its own fixed monetary or custodial penalty for a breach: Law No. 2163-VIII's Article 12 is a generic cross-reference to whatever civil, administrative or criminal liability already exists under other legislation for the underlying conduct, rather than a penalty of its own, and Law No. 1882-IX's final provisions confirm that a dedicated sanctions regime for its own operator duties had not yet been drafted as of the text reviewed here.
Because zakon.rada.gov.ua, the Verkhovna Rada's official consolidated-legislation database, and its data.rada.gov.ua open-data sibling both return a site-wide robots.txt disallow for every crawler, both instruments below are pinned to a fixed Internet Archive Wayback Machine snapshot of the official zakon.rada.gov.ua page, since the live host answers every crawler with the same disallow; the archived text is the government's own, unaltered, and the snapshot used for Law No. 2163-VIII records the text as current to 3 April 2025 (basis: Law № 4070-IX), while the document's own status card, read on a later, shell-only snapshot, names a further amendment, Law № 4336-IX, in force from 19 October 2025, not reflected in the text pinned here.
No product-security or market-placement duty on a software or connected-device manufacturer, independent of the critical-infrastructure-owner regime above, was located; nor was a general "reasonable security" or information-security-programme statute with no sector gate.
This review could not confirm whether Ukraine has introduced a dedicated NIS2-aligned reform bill comparable to the pending reforms this topic's Spain row documents; if one exists, it was not found in the sources this review could reach.
This jurisdiction's own privacy row, the Law "On the Protection of Personal Data" (Law No. 2297-VI, in force 1 January 2011), carries Ukraine's data-protection regime, including the cross-reference Law No. 2163-VIII's own Article 6(5) makes to it for a cybersecurity incident's personal-data component, and is researched there rather than restated here.
The Criminal Code's Article 361 (unauthorized interference with an information, electronic-communications or telecommunications system) and Article 361-1 (creating or distributing malicious software) are intruder-offense provisions that bind the person doing the interfering rather than the operator, and are researched on this jurisdiction's scraping-topic row rather than here.