Law Messenger
New sector-specific rules adopted for categorizing critical information infrastructure in financial services
11.02.2026
Earlier, we reported on key amendments introduced in 2025 to Federal Law No. 187-FZ on the Security of Critical Information Infrastructure in the Russian Federation (the “CII Law”).
On 6 February 2026, the Russian Government adopted Decree No. 92 (the “Decree”), establishing sector-specific rules for categorizing critical information infrastructure (CII) in the banking sector and other segments of the financial market[1]. The new regulation, which entered into force on 15 February 2026, requires CII entities to take immediate compliance actions.
The Decree establishes the procedure for assessing whether a CII facility meets the statutory significance criteria and applicable threshold indicators for the purpose of assigning it to one of the designated significance categories. It also formalizes the methodology for calculating the values of relevant significance indicators, taking into account the specific characteristics of particular facilities.
Scope of application
Under the Decree, the sector-specific categorization rules apply to the following financial market participants:
- Government authorities and/or legal entities exercising functions or powers in the banking sector and other segments of the financial market (including their subordinate organizations);
- Credit institutions;
- Non-credit financial institutions;
- Participants in the national payment system; and
- Providers of professional services in the financial market,
provided that they own, lease, or otherwise lawfully possess information systems, information and telecommunications networks, or automated control systems (collectively, “IT systems”) that support the performance of their functions as CII entities in the financial market.
Key compliance requirements
The adoption of sector-specific categorization rules automatically triggers the need to revisit prior categorization decisions—either confirming the assignment of a significance category or reassessing whether such categorization is required[2].
If an IT system is recognized as a CII facility, the company must implement a comprehensive set of measures designed to ensure its security.
In addition, as of 1 September 2025, CII entities are required to maintain continuous interaction with the State System for Detection, Prevention and Elimination of Consequences of Computer Attacks (GosSOPKA). This includes installing technical tools for detecting computer attacks and incidents (in particular, tools for identifying indicators of compromise), and reporting detected incidents to the authorized state body.
Furthermore, CII entities must use domestic software at designated significant CII facilities.
What qualifies as a CII facility?
According to the Decree, the determination of whether an IT system constitutes a CII facility must be based on the following criteria:
- List of typical sector-specific CII facilities. A draft list is currently under review by the Russian Government[3]. The list includes, inter alia, the following systems:
- Remote banking service systems
- Automated banking systems
- Transaction processing systems
- Financial transaction recording systems
- Client account management systems of non-state pension funds and microfinance organizations
- Insurance contract, payment, claims and reinsurance accounting systems
- Credit information systems responsible for collection, processing, storage and provision of credit data
- Government-approved significance criteria[4]
Importantly, an IT system may qualify as a CII facility even if operates in another sector, provided that it supports the company’s activities in the financial market. Accordingly, the categorization exercise must take into account not only lists of typical CII facilities applicable to the financial market, but also those relevant to other sectors.
Implications for companies
The adoption of sector-specific rules means that companies qualifying as CII entities must complete a number of formal compliance steps.
In particular, they are required to:
- Establish a categorization commission, comprising the head of the CII entity, experts in IT, telecommunications, process/industrial safety and information security, and other relevant personnel as necessary
- Identify CII facilities and assign them an appropriate significance category in accordance with the Government-approved significance criteria and the newly adopted sector-specific rules
- Submit to the Federal Service for Technical and Export Control (FSTEC of Russia) the formal report adopted by the categorization commission
Liability for non-compliance with the CII Law
Failure to comply with the requirements of the CII Law may result in administrative liability for legal entities and their officers, including administrative fines up to RUB 500,000 for legal entities and up to RUB 50,000 for individual officers.
In cases where non-compliance causes actual damage to CII, responsible officers may also face criminal liability, including imprisonment for up to five years and a criminal fine of up to RUB 1,000,000.
Our recommendations and how B1 can help
In the coming months, companies should prioritize the following measures:
- Assess whether they qualify as CII entities
- Conduct CII categorization in accordance with the updated lists of typical CII facilities and the newly adopted sector-specific rules
- Transition to domestically developed software and hardware solutions
Given the current uncertainty surrounding transition periods, we recommend proactively planning compliance measures—such as migrating to Russian-hosted services or preparing documentation required for registration of domestic software and databases in the relevant state registers and lists.
The B1 team is ready to assist clients with:
- Determining their status as CII entities
- Legal advisory throughout the CII categorization process, including helping the company prepare its position for discussions with regulatory authorities
- Ongoing compliance monitoring
- End-to-end support for migration to domestic software solutions, including preparation of all necessary documentation
Show references
-
[1] URL: http://publication.pravo.gov.ru/document/0001202602070010?ysclid=mlhxg7axhd992845491
-
[2] Russian Government Decree No. 127 dated 8 February 2018, clause 21
-
[3] URL: https://regulation.gov.ru/projects/157304/?ysclid=mlhvq8j9dh864859819
-
[4] Russian Government Decree No. 127 dated 8 February 2018
AUTHORS
Natalia Aristova
B1 Partner
Legal Services. Expert in corporate, finance and banking law, sanctions compliance, energy and environmental law
Contact
Dmitry Semenov
B1 Director
Legal Services, Tax, Law and Business Support. Specializes in a broad range of intellectual property matters
Contact
Polina Bychenok
B1 Assistant Manager
Legal Services
Contact
Ivan Solonkin
B1 Advanced Staff
Legal Services
Contact
OTHER PUBLICATIONS
View all
New sector-specific rules adopted for categorizing critical information infrastructure in financial services
On 6 February 2026, the Russian Government adopted Decree No. 92, establishing sector-specific rules for categorizing critical information infrastructure (CII) in the banking sector and other segments of the financial market. The new regulation, which entered into force on 15 February 2026, requires CII entities to take immediate compliance actions.
11.02.2026
Extended producer responsibility (EPR): what has changed since 1 January 2026 and how it affects businesses
Federal Law No. 495-FZ of 28 December 2025 “On Amendments to Article 29¹ of the Federal Law ‘On Production and Consumption Waste’ and Certain Legislative Acts of the Russian Federation” (“Law No. 495-FZ”) was enacted on 31 December 2025 to introduce the new EPR transition timeline for importers from non-EAEU countries.
14.01.2026
New U.S. sanctions
On 22 October 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) issued a press release announcing the imposition of new sanctions against Russia. Below is an overview of the new restrictions and licenses.
27.10.2025
Changes in the regulation of the security of critical information infrastructure (CII)
In 2025, Federal Law No. 187-FZ “On the Security of Critical Information Infrastructure of the Russian Federation” dated 26 July 2017 was significantly amended to strengthen CII technology independence and security. The amendments, introduced by Federal Law No. 58-FZ dated 7 April 2025 (effective 1 September 2025) and Federal Law No. 325-FZ dated 31 July 2025 (effective 1 March 2026), determine CII entities and establish new obligations for them. We highlight the key developments that require companies to promptly adapt their approaches to categorizing CII facilities and building the software mix.
20.10.2025
Overview of potential restrictions resulting from the 19th EU sanctions package
On 19 September 2025 the European Commission presented member states of the European Union with proposals for a 19th package of sanctions against Russia. At the time of writing the package has not yet been approved by the EU Council and its scope and content remain under discussion. Below is a brief summary of the proposed measures based on public statements made by the EU Commission and individual EU officials as well as information available in the mass media as of 7 October.
07.10.2025
Changes to the rules for the distribution of audiovisual works in Russia: new requirements and restrictions
On 31 July 2025 a new federal law was published which amends the rules for the issuance and revocation of distribution certificates1 for audiovisual works and may have a major impact on the activities of owners of streaming services and social networks in Russia. The changes will come into force on 1 March 2026.
28.08.2025
New Russian Civil Code provisions regarding compensation for infringements of intellectual property rights
Federal Law No. 214-FZ “On Amendments to Part Four of the Civil Code of the Russian Federation”, which was published on 7 July 2025, transforms the system of compensation for infringements of intellectual property rights.
26.08.2025