This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

187-FZ "On the Security of Critical Information Infrastructure"

Information Security

187-FZ is the law on the security of critical information infrastructure, establishing requirements for the protection of CII facilities.

What is 187-FZ "On the Security of Critical Information Infrastructure"

Federal Law No. 187-FZ "On the Security of Critical Information Infrastructure of the Russian Federation" was adopted on July 26, 2017 and establishes mandatory requirements for the protection of CII facilities — information systems, automated control systems and communication networks that are critical for government administration, defense, economy and life support of the population. The law applies to organizations in healthcare, transport, communications, energy, finance, science, defense and nuclear industries, as well as other sectors that ensure the vital activity of the state. Compliance with the requirements is controlled by the FSTEC of Russia (Federal Service for Technical and Export Control), and administrative fines (up to 1 million rubles for organizations) and criminal liability (under Article 274.1 of the Criminal Code of the Russian Federation — up to 8 years of imprisonment) are provided for violations. Violation of the law entails not only financial losses but also a threat to national security, so compliance with 187-FZ is critically important for all CII entities. To protect CII facilities, it is necessary to implement comprehensive security systems, including SIEM systems and DLP solutions for monitoring and incident prevention, as well as the use of certified information protection tools.

187-FZ: CII categories and security requirements Infographic on the critical information infrastructure law. Object categories (1-3), mandatory requirements (certified crypto, attestation) and liability for violations. 187-FZ: security of critical information infrastructure Object categories First category Federal scale Second category Regional scale Third category Municipal scale Requirements Security system Certified cryptographic means Incident notification Object attestation Liability Administrative Up to RUB 1 million Criminal Up to 8 years Disqualification CII industries Energy Transport Banking Healthcare Communications 187-FZ: CII object categories, security requirements and liability for violations
187-FZ "On the Security of Critical Information Infrastructure" — term diagram

Categorization of CII facilities

The law divides critical information infrastructure facilities into three categories of significance depending on the potential damage in case of a security breach. The first category — facilities whose security breach could lead to an emergency of federal scale, significant damage to the economy, defense or state security. The second category — facilities whose accident creates a threat on a regional scale and could disrupt the life support of the population or the transport infrastructure of a constituent entity of the Russian Federation. The third category — facilities whose incidents could cause damage on the scale of a municipality or an individual organization. Particularly significant facilities — a separate category for facilities of special importance for defense, security and public order. Categorization is carried out according to departmental methodologies that take into account the social, political and economic consequences of possible incidents. The results of categorization are sent to the FSTEC of Russia within 10 working days from the moment the categorization act is approved. Different requirements for the level of protection and the frequency of inspections are established for facilities of different categories.

Obligations of CII entities

CII entities (organizations that own CII facilities) are obliged to fulfill the following requirements established by the law and by-laws. Create a security system for facilities — develop and implement organizational and technical protection measures, including security policies, regulations, instructions, and appoint responsible persons. Conduct categorization — determine the category of significance of each CII facility within the established period (for new facilities — within 1 year from the moment of commissioning) and send the information to the FSTEC. Use certified CIPF tools — apply cryptographic protection tools certified by the FSB of Russia to protect information during transmission and storage. Provide technical protection measures — protection against unauthorized access (UAA), antivirus protection, data integrity control, encryption of communication channels, backup, and security event monitoring. Report incidents — promptly notify the FSTEC of Russia about computer incidents at CII facilities and interact with the State System for Detecting, Preventing and Eliminating the Consequences of Computer Attacks (GosSOPKA). Conduct certification — confirm the compliance of the protection system with security requirements by conducting certification tests. Since 2025, a ban on the use of foreign software at CII facilities has been introduced (except for cases where there are no domestic analogues).

Liability for violation of 187-FZ

Administrative and criminal liability is provided for non-compliance with the requirements of the law. Administrative fines — for officials up to 500,000 rubles, for organizations up to 1,000,000 rubles (under Article 13.14 of the Code of Administrative Offenses of the Russian Federation for violating information protection requirements). Fines are also provided for failure to comply with FSTEC orders, failure to provide information or providing inaccurate information. Criminal liability — Article 274.1 of the Criminal Code of the Russian Federation "Unlawful influence on the critical information infrastructure of the Russian Federation" provides for punishment of up to 8 years of imprisonment for the creation, distribution or use of malicious programs aimed at CII facilities. Disqualification — for officials, disqualification for up to 3 years is provided for repeated violation. Suspension of activity — the court may decide to suspend the organization's activity until violations are eliminated. To minimize risks, it is recommended to conduct a regular audit of security systems, promptly update protection tools and undergo certification of CII facilities within the established timeframes.

Frequently asked questions

What is CII and who does the 187-FZ law affect?

CII (critical information infrastructure) is information systems, telecommunication networks and automated control systems used in vital spheres of the state. Law 187-FZ obliges government bodies and companies from critical sectors (banks, transport, communications, energy, healthcare) to protect their systems from cyber attacks and report computer incidents. To fulfill the requirements of the law, it is necessary to use certified CIPF tools and other protection measures.

What is 187-FZ in simple words?

187-FZ is a law that obliges vital organizations to protect their computers, networks and databases from cyber attacks. Its main goal is to prevent hackers from turning off the electricity, stopping trains, hacking hospitals or disrupting the work of banks. The law requires companies to categorize systems, implement protection and report attacks to the FSTEC and the FSB. Firewalls and intrusion detection systems are used to protect CII facilities.

What must a CII entity do according to 187-FZ?

A CII entity is obliged to categorize facilities and send the results to the FSTEC, create a security system using certified tools, implement technical protection measures (access control, encryption, antivirus protection), and also report computer attacks and interact with GosSOPKA. It is recommended to use SIEM systems and DLP solutions to ensure the security of CII facilities.

Who falls under the scope of 187-FZ?

Government bodies and Russian legal entities that own information systems in critically important sectors fall under the scope of the CII law: healthcare, transport, communications, energy, banking, defense, nuclear, mining, metallurgical and chemical industries. Individual entrepreneurs are excluded from this list. Biometric systems and access control systems (ACS) are used to identify and authenticate users at CII facilities.

What categories of CII facility significance exist?

187-FZ establishes three categories of CII facility significance. The first category — facilities whose security breach could lead to an emergency of federal scale. The second category — facilities whose accident creates a threat on a regional scale. The third category — facilities whose incidents could cause damage on the scale of a municipality. Particularly significant facilities for defense and security are also distinguished. Various cryptographic protection tools are used to protect facilities of different categories.

What is a CII facility according to 187-FZ?

A CII facility is information systems, information and telecommunication networks and automated control systems of critical information infrastructure entities. These include process control systems (SCADA), databases, data transmission networks and other equipment that ensures the functioning of critical sectors. Certified tools, including firewalls and access control systems, are needed to protect such facilities.

What amendments to 187-FZ come into force on September 1, 2025?

Amendments to 187-FZ tightening CII security requirements come into force on September 1, 2025. Mandatory certification of protection tools for all categories of facilities is introduced, requirements for incident monitoring and interaction with GosSOPKA are strengthened. The list of facilities subject to mandatory certification is also expanded. A ban on the use of foreign software at CII facilities is introduced (except for cases where there are no domestic analogues). To prepare for the changes, it is recommended to undergo certification of CII facilities. Read more about government regulation of the industry in the article Government regulation in IT.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate 187-fz "on the security of critical information infrastructure" into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm