Ukraine's cyber regulator has done something unglamorous and useful: it wrote down how it will check whether critical infrastructure operators are actually defended. Order No. 604 of the Administration of the State Service of Special Communications and Information Protection (SSSCIP, or Derzhspetszviazku), dated 7 August 2026, approved a Methodology for state cybersecurity control. It took effect on 18 September 2026, according to Ligazakon's legal news service. The Order separates ongoing monitoring from formal inspections and introduces a uniform inspection-report form. Its design is mostly right, and the open questions are about how it will be used.
The strongest case for tough supervision
The case for hard-edged oversight in Ukraine is stronger than almost anywhere else. Operators face a state-level adversary that attacks continuously. When Parliament passed the cybersecurity law (bill 11290) on 27 March 2025 with 240 votes, the debate followed a reported Russian attack on Ukrzaliznytsya just days earlier. The law aligns Ukraine with the EU's NIS2 Directive and entered into force on 20 April 2025. Law firm Asters notes that more than 30 implementing acts were expected to fill in the practical rules. A statute without an inspection method is a wish list. Regulators who can't scope, document and follow up on inspections end up with arbitrary checks or no checks. Order 604 addresses exactly that gap.
What the Order actually does
As reported by Ligazakon, monitoring examines reporting, cyber-defence status indicators and how far mitigation measures have been implemented. Inspections instead test compliance against specific legal requirements. The distinction matters because it puts routine oversight in the lower-friction channel. An operator whose indicators look healthy is not pulled into a full inspection just to be checked.
Inspections can be planned using risk indicators. These include prior assessment results, earlier inspection findings, unfulfilled compliance orders, specific cyber incidents and overdue annual evaluations. Ligazakon stresses that these indicators do not automatically put an entity on the annual inspection plan, so the regulator keeps discretion. After an inspection, the SSSCIP can issue a compliance order, draw up an administrative-offence protocol or issue recommendations. All of this goes into a uniform report form recording the requirement, the actual circumstances, the evidence and the conclusion.
The form is the most underrated piece. A standard structure that links each finding to a named requirement and to evidence gives operators something to contest on the facts. It also lets the regulator compare inspections across sectors.
It fits a larger measurement stack
Order 604 is the latest step in a stack the SSSCIP has built this year. In July the agency published a risk-assessment methodology, Order No. 402 of 2 June 2026. It applies to state bodies, critical infrastructure operators and owners of critical information infrastructure. It requires assessments at least annually or after significant system changes, and it uses a Bayesian method to refine risk estimates as new incident information arrives. Earlier, under Order No. 285 of 16 April 2026, the SSSCIP set out a unified way to score cyber-defence status. It uses a weighted average across six functions: governance, identification, protection, detection, response and recovery. If any basic function scores below 20%, the overall status is automatically "critical".
Taken together, the design is coherent. Operators assess risk, score themselves, report, get monitored, and only then face inspections triggered by the indicators those steps generate. That is close to how mature regulators use supervisory data.
Where proportionality could slip
The pro-innovation worry is not that Ukraine is regulating. It is that a scoring system can become a punishment system.
- Score-driven inspections. An automatic "critical" status below 20% on one function is a blunt trigger. It should lead to targeted support and a remediation plan before it leads to an offence protocol. The Order's own wording, that indicators do not automatically trigger inclusion in plans, is the right safeguard. Practice should follow it.
- Incidents as inspection triggers. Using specific cyber incidents to plan inspections can penalise operators who detect and report honestly, while those who under-detect look clean. If reporting an incident raises the odds of an offence protocol, operators have a reason to say less. The SSSCIP should publish how it separates a victim of a state-backed attack from a negligent operator.
- Compliance paperwork versus defence. In wartime, scarce engineers are better used patching and hardening than preparing documentation. Reports should ask for evidence operators already generate.
- Recommendations first. The Order provides for recommendations as well as binding orders and protocols. A regulator that defaults to the softer tools when operators cooperate will get more security per hryvnia than one that leads with protocols.
What to watch
Three indicators will show whether the methodology works. First, the share of inspections that end in recommendations or compliance orders rather than administrative-offence protocols. Second, whether the SSSCIP publishes anonymised aggregate results by sector. Third, whether operators can challenge factual findings in the uniform report. None of this is yet visible, because the methodology has only been in force since 18 September.
The verdict is qualified but positive. Separating monitoring from inspection, tying inspections to declared risk factors and standardising the report are design choices that make regulation predictable, and predictability is what lets operators invest with confidence. The risk lies in enforcement culture. If the SSSCIP treats the methodology as a diagnostic tool, it strengthens a national resilience effort that has already withstood years of sustained attack. If it becomes a scorecard for penalties, it will discourage the openness that wartime defence depends on.