LOGIC TELECOM
Tech worldJuly 19, 20262 min read

New FSTEC requirements for government information systems took effect in 2026

FSTEC Order No. 117 updated security requirements for Russian government information systems. Here is what system owners and contractors should review.

Protected government information system
Contents

Updated security requirements for Russian government information systems took effect on 1 March 2026. They were established by FSTEC Order No. 117 of 11 April 2025, officially published on 17 June 2025.

What changed

The order updates how a security system for a government information system is designed, managed and assessed. The applicable controls depend on the system’s protection class, threat model and processed information.

A contractor’s licence does not replace system classification, threat modelling, organisational controls or evidence that the required measures work.

Who is affected

  • owners and operators of government information systems;
  • developers and integrators building or modernising them;
  • infrastructure and security contractors responsible for specific work.

A commercial system does not automatically fall under the order merely because it connects to a government service. Scope depends on the system’s legal status, contracts and other applicable rules.

What owners and contractors should review

  1. Confirm the protection class, boundaries and current threat model.
  2. Compare existing documentation and controls with Order No. 117.
  3. Define the responsibilities of the owner, operator, cloud provider and integrator in the contract.
  4. Test backup, restoration and logging in practice.
  5. Verify that each contractor holds the licences required for the work actually delegated to it.

Infrastructure implications

Resilience and an SLA support availability, but do not by themselves prove security compliance. Ask a provider for its shared-responsibility model, incident process, audit evidence and rules for access to logs.

Conclusion

Order No. 117 calls for a system-specific gap analysis, not a one-certificate checklist. The final set of controls must be determined for the particular information system with qualified security and legal input where needed.

Our guide to FSTEC and data protection explains the distinction between a contractor licence, operator duties and system controls.

Primary source: ConsultantPlus: full text of FSTEC Order No. 117

TrendsSecurityInfrastructure

Read also