IQusion is an active licensee of the State Service for Special Communications for information security assessment

August 13, 2026 · 4 min

On 11 August 2026, the State Service for Special Communications and Information Protection of Ukraine published an updated list of business entities authorised to provide services for assessing the security of information that does not constitute a state secret. IQusion IT LLC (IQusion) is included in the list with the status of "Active". The basis is the Order of the Administration of the State Service for Special Communications No. 10 dated 4 January 2017.

What this licence means

IQusion has been operating in this field since 2017, and the current update of the official list confirms the retention of its licensee status after more than nine years of operation. For clients, this status is of practical importance in projects where legislation or regulatory procedures require the involvement of a contractor authorised to perform the relevant type of activity in the field of technical protection of information.

The licensing conditions, approved by Resolution of the Cabinet of Ministers of Ukraine No. 821, establish requirements for the organisation of such work, in particular, for the personnel, organisational, and technological support of the contractor. The active status of the licensee confirms the company's right to carry out the relevant type of activity in the field of technical protection of information in accordance with the established licensing conditions.

The formulation "information that does not constitute a state secret" does not mean that it refers only to open information. The object of assessment can be systems processing personal data, official, confidential, commercial, and other restricted information. The legal regime of information and specific requirements for its protection are determined separately for each object.

Work related to the protection of state secrets belongs to another category and is not covered by this type of licence.

What security assessment can include

The objects of assessment can be information and information-communication systems, their software and hardware components, security tools, as well as documentation defining the architecture, configuration, and operating procedures of the system.

The specific scope of work depends on the purpose of the system, its architecture, categories of information, applicable regulatory requirements, and the procedure for which the assessment results are required.

The work, as a rule, begins with defining the object and boundaries of the assessment. The composition and interaction of components, information flows, operating conditions, applied security mechanisms, and the set of documentation are analysed.

Particular attention is paid to the correspondence between how the system should be protected according to the documentation and how these mechanisms are actually implemented.

Depending on the task, the following may be verified:

  • design, technical, organisational, administrative, and operational documentation;
  • user identification and authentication mechanisms;
  • access control and segregation of duties;
  • event registration and logging;
  • integrity control mechanisms;
  • backup and recovery;
  • actual configurations of software and hardware security tools;
  • performance of declared security functions under specified conditions.

If provided for by the task and the relevant regulatory procedure, expert testing may be conducted according to an agreed programme and methodology.

The results of the work are documented, recording conclusions, identified non-conformities, and, depending on the procedure, recommendations or baseline data for subsequent remediation of deficiencies.

What the client receives

The practical value of the assessment lies in obtaining an objective understanding of the actual security state of the system and identifying discrepancies between requirements, documentation, and the real implementation of security mechanisms.

This allows to:

  • identify non-conformities before the project is completed;
  • prioritise necessary refinements;
  • align documentation with the actual architecture and configuration of the system;
  • reduce the risk of expensive changes in the final stages of system creation or modernisation;
  • prepare the system and necessary materials for subsequent procedures, if they are stipulated by regulatory requirements.

That is why it is advisable to involve specialists not only after the completion of system creation, but also at the stage of its design or modernisation. In this case, the identified requirements and comments can be taken into account in the architecture, configuration of security tools, and documentation even before the system is put into operation.

IQusion's experience

IQusion has held an active licence for this type of activity since 4 January 2017. During this time, requirements for information systems, technological approaches, and the regulatory environment have changed significantly, but the need for a professional and formalised assessment of implemented security mechanisms remains relevant.

The IQusion team can join the project at an early stage, helping to define the applicable requirements, the object and boundaries of the assessment, the list of necessary baseline materials, and the optimal sequence of work for a new or modernised information system.

Sources