Skip to content

Migrating Banking Systems to the Cloud: Meeting NBU Requirements for Cybersecurity and Data Sovereignty

Digital transformation is an integral part of the financial sector's development in Ukraine, especially amidst growing cyber threats and wartime challenges. Cloud technologies offer banks and fintech companies unprecedented flexibility, scalability, and resilience, which are crucial for ensuring business continuity. However, integrating cloud solutions into banking infrastructure demands not only technical expertise but also a deep understanding and strict adherence to the National Bank of Ukraine's (NBU) regulatory requirements for cybersecurity, data protection, and data sovereignty.

The choice of cloud infrastructure architecture and provider becomes a strategic decision that defines not only operational efficiency but also the institution's compliance resilience. It is necessary to find a balance between the advantages of cloud technologies and the need for strict adherence to NBU regulatory requirements, which may limit the choice of providers and architectural solutions, as well as increase compliance costs.

New Realities and NBU Regulatory Framework

The foundational document regulating the use of cloud technologies in Ukraine's financial sector is the NBU Board Resolution No. 99 of August 25, 2025, "On Approval of the Regulation on the Procedure for Applying Cloud Computing Technology." This resolution formalizes the use of cloud services for banks, financial service providers, payment system operators, and participants. It sets clear requirements for selecting cloud providers, concluding agreements, risk management, data protection, ensuring operational continuity, and informing the National Bank.

Resolution No. 99 permits the use of various cloud service models, including IaaS (Infrastructure as a Service), PaaS (Platform as a Service), SaaS (Software as a Service), and SECaaS (Security as a Service), as well as private, public, hybrid, and community clouds. For institutions that were already using cloud services before Resolution No. 99 came into effect (November 1, 2025), a transition period until May 1, 2026, was established to bring agreements into compliance with the new requirements and inform the NBU.

It is also important to consider NBU Board Resolution No. 42 of March 8, 2022, which, under martial law, allowed banks to use cloud services with equipment located in the European Union, the United Kingdom, the United States of America, and Canada. This provision is valid during the martial law period and for two years after its cancellation, offering additional options for provider selection.

Data Sovereignty: Where Do Responsibilities Lie?

The issue of data sovereignty is one of the most sensitive aspects of migrating banking systems to the cloud. The NBU requires financial institutions to comply with Ukrainian legislation on the protection of personal and other data, regardless of where it is physically stored. This means the bank remains responsible for maintaining banking secrecy and customer personal data.

If a foreign cloud provider is chosen, the National Bank's requirements for cloud technologies become even stricter. Banks must carefully analyze the jurisdiction where data is stored and ensure that the provider's policies comply with Ukrainian regulations, particularly regarding data access and disclosure. It is essential to ensure that any restricted-access data, including banking secrecy, is protected in accordance with Ukrainian law, even if it is located outside Ukraine.

Cybersecurity in the Cloud: Shared Responsibility Model and NBU Requirements

Migration to the cloud does not absolve a financial institution of responsibility for cybersecurity. Instead, it introduces a Shared Responsibility Model. Under this model, the cloud provider is responsible for the security "of the cloud" (i.e., the underlying infrastructure on which services run), while the client (bank) is responsible for security "in the cloud" (i.e., its data, applications, configurations, and access).

The NBU requires banks to clearly designate responsible individuals for the implementation and use of cloud services. Banks are obligated to monitor the provider's access to restricted information and track data events in the cloud, including cyber incidents and failures. The cloud provider, in turn, must not only comply with international information security standards but also provide independent certification of compliance annually. They must also ensure a transparent contractual model, security reporting, incident management, and disclosure of the partner chain.

General requirements for risk management, including information security risk as a component of operational risk, are defined by NBU Board Resolution No. 64 of June 11, 2018. This provision requires banks to adopt a thorough approach to building and operating a risk management system appropriate to their business activities.

Cloud Provider Selection Criteria: More Than Just Price

The selection of a cloud provider for critical banking systems must be based on a comprehensive analysis that goes beyond just the cost of services. IT department heads and CISOs should consider the following key criteria dictated by NBU requirements:

  • Data Center (DC) Location: Ensure the provider's DCs are located in jurisdictions that comply with NBU requirements, especially considering Resolution No. 42 and data sovereignty issues.
  • Security Certifications and Standards: The provider must have up-to-date international certifications (e.g., ISO 27001, SOC 2 Type II) and confirm them annually. It is also important for the provider to be able to provide security reports.
  • Contractual Model and SLA: The contract must be transparent, clearly define areas of responsibility (Shared Responsibility Model), service level guarantees (SLA), and incident management mechanisms.
  • Audit and Monitoring Capabilities: The bank must have the ability to conduct its own security control of the provider's system, monitor data access, and track events.
  • Business Continuity and Disaster Recovery (BCP/DR) Plan: The provider must have robust BCP/DR mechanisms, and the bank must develop its own plan, including recovery scenarios in case of provider failure and protocols for switching to another provider.
  • Supply Chain Management: The NBU requires disclosure of the provider's partner chain. The bank must assess risks associated with the provider's subcontractors.
  • Support for Cryptographic Protection Tools: Ensure the provider supports the use of both domestic information cryptographic protection tools and those compliant with the legislation of the country where the equipment is located.

Cloud Infrastructure Audit Checklist

To ensure compliance with NBU requirements, banks must regularly audit their cloud infrastructure. Below are key points for such a checklist:

  • Does the current location of the cloud provider's data centers comply with NBU requirements, particularly Resolution No. 42?
  • Does the provider have up-to-date international security certifications (ISO 27001, SOC 2 Type II) and provide annual confirmations?
  • Are the areas of responsibility of the bank and the provider clearly defined in the cloud service agreement (Shared Responsibility Model)?
  • Are there internal bank documents defining responsible individuals for cloud service usage and monitoring procedures?
  • Is there regular monitoring of the provider's access to restricted data and tracking of cyber incidents?
  • Has a business continuity plan been developed and tested, including scenarios for provider failure and switching to an alternative solution?
  • Do data protection measures (encryption, backup, access control) comply with Ukrainian legislation and NBU requirements?
  • Is regular risk assessment conducted related to the use of cloud services, in accordance with NBU requirements (Resolution No. 64)?
  • Is the bank and/or regulator's ability to audit the cloud infrastructure ensured?
  • Have NBU requirements regarding disclosure of information about client ties to the aggressor state been considered when selecting and using cloud services?

Migrating banking systems to the cloud is a complex but strategically important step. The success of this process depends on a deep understanding and unwavering adherence to NBU regulatory requirements. Only a thorough provider selection, well-thought-out architecture, and constant monitoring will allow Ukrainian banks to fully leverage the benefits of cloud technologies while maintaining the highest level of cybersecurity and compliance with national legislation, which is the key to stability and trust in Ukraine's financial sector.

Sources

  1. 01chambers.comThe National Bank of Ukraine to regulate the use of cloud technologies by financial institutions | Article | Chambers and Partners
  2. 02deloitte.uaUpdated Cybersecurity Requirements for Non-Bank Financial Institutions | Deloitte Ukraine
  3. 03rasons.legalDecree of the Board of the National Bank of Ukraine No. 99 approved the Regulation on the use of cloud computing technologies
  4. 04sdcenter.org.uaInnovative Mechanisms of State Regulation of Information Security of Financial Institutions in Ukraine in the Context of DORA Implementation

Does any of this match your situation?

Tell us where you are now — we will suggest a practical route for infrastructure, cloud or security.

Discuss a project