NBU Resolution 143
Resolution of the Board of the National Bank of Ukraine of 9 December 2025 No. 143 sets information-security and cyber-protection measures for financial service providers that are not payment institutions. The full summary is the knowledge-base article. This page is the short map.
Who it applies to
The knowledge-base summary names insurers, credit unions, financial companies, and pawnshops. It says the resolution does not apply to payment service providers, to certain other entities, or to postal operators with the right to trade in currency values. Payment providers in this cluster are under Resolution 123, not under 143.
What the summary says it requires
The objects of protection named in the summary are insurance secrecy, financial-service secrecy, and the information and communication systems that support core business processes or interact with NBU systems. Providers must apply measures across the lifecycle of those systems and use a risk-based approach, including a process for cyber risk and information-security risk. The article then goes through the structure and the requirement areas of Sections II and III. Those sections stay in the article, not on this page.
Records, after the resolution is clear
The article’s implementation section points at a custom or local framework in SecBoard compliance, so controls and evidence can be mapped, and at the risk, asset, access, incident, document, training, and third-party modules for the operational records. That is help with the file. It is not an NBU opinion and not a certificate.