FSTEC and data protection: what business needs to know
What an FSTEC licence confirms, how it relates to personal-data protection and what to verify with an infrastructure contractor.

Contents
For banks, healthcare and the public sector, data protection is not a “nice to have” but a matter of regulatory compliance. FSTEC is often at the center of this topic. Let’s break down what it means for business and what to look for when choosing a provider.
Who FSTEC is
FSTEC is the Federal Service for Technical and Export Control. It sets requirements for information protection, including personal data and data in state information systems. An FSTEC license confirms that an organization is entitled to provide technical information-protection services.
Why it matters for business
If your business works with customer personal data (and almost every business does), the requirements for protecting it also apply to the infrastructure where that data is stored and processed.
A licence confirms the provider may perform specified work. It does not certify the entire infrastructure automatically or remove the duties of the personal-data operator or information-system owner.
What a licensed contractor provides
- the legal ability to perform licensed categories of security work;
- relevant expertise and project documentation;
- a clearer allocation of responsibility for design and operation.
The customer still determines applicable requirements, approves the threat model, manages access processes and oversees contract performance. FSTEC requirements do not exhaust the regulatory landscape: cryptographic controls may bring separate FSB requirements into scope, and the final control set must be determined for the particular information system.
FSTEC and personal-data law
Russian Federal Law No. 152-FZ defines the duties of a personal-data operator. Technical and organisational controls depend on the system type, protection level, threat model and other applicable acts. FSTEC Order No. 117 applies to government information systems from 1 March 2026; other systems follow different sets of rules.
The practical sequence starts with an inventory of data and system boundaries, followed by classification, threat modelling, control selection, implementation and evidence collection. Owners of a government information system should also review our summary of FSTEC Order No. 117.
Moving a system to the cloud does not transfer the data operator’s duties to the provider. The contract should allocate responsibility for the facility, virtualisation, operating systems, applications, accounts, backups, monitoring and incident notification. See the comparison of IaaS and an in-house data centre for deployment trade-offs.
What to look for when choosing a provider
- Verify the licence and its permitted work in the official register.
- Put responsibility for operating systems, applications, accounts, backups and incident response in the contract.
- Request information on facilities, segmentation, logging and staff access.
- Define the evidence the provider supplies for audit or attestation.
- Check the exit plan: data export, deletion deadlines and migration assistance.
Conclusion
An FSTEC licence is an important contractor criterion, not a ready-made compliance seal for the complete system. A sound project starts with data classification and a threat model, then proves controls through documentation and recurring checks.
Reassess requirements after architecture, data, integration or threat-model changes. Compliance work continues after launch through access reviews, log analysis, recovery testing and a documented change process.
This material is general information, not a substitute for legal analysis, system classification, threat modelling or selecting controls for a specific project.


