Habr•September 1, 2026•🇷🇺Translated from Russian

FSTEC Order 60 Expands Attestation Rules to Municipal Systems, Defense Industry and Personal Data Operators

Russian regulators have significantly widened the circle of organizations required to perform attestation of information systems starting 1 September 2026. The key document, FSTEC Order No. 60 of 27 February 2026, amends the earlier FSTEC Order No. 77 of 29 April 2021 and changes the very definition of entities covered by the attestation procedure.

The updated rules now explicitly apply to state and municipal information systems, including municipal personal data systems; industrial control systems at defense-industry organizations, including CNC machine tools; and protected premises used for confidential negotiations. The order also covers any information systems belonging to state bodies, state unitary enterprises or state institutions that are not formally classified as state systems, as well as critical information infrastructure objects, non-state personal data operators and industrial control systems at critically important or potentially hazardous facilities.

Two new articles introduce concrete control methods. Article 31¹ states that post-attestation monitoring must include vulnerability analysis and penetration testing. Article 16¹ makes penetration testing mandatory for state information systems and other systems of state bodies, unitary enterprises and institutions that have first or second protection class and are connected to the internet or interact with external systems, with the sole exception of encrypted VPN channels using certified cryptographic means.

Reporting deadlines have also changed. Article 32 now requires submission of control results to FSTEC at least once every three years and no later than five working days after completion of the control. Failure to meet the deadline can lead to suspension of the attestation certificate. Only organizations holding an FSTEC license that explicitly includes rights to conduct attestation tests and protection control against unauthorized access may perform the work.

A second document, FSB Order No. 297 of 6 August 2026, implements new incident-reporting obligations for every state institution under the amended Article 16 of Federal Law 149-FZ. Each school, hospital or other state-funded body must independently conclude an interaction regulation with NKTSKI, obtain a personal cabinet and transmit information about incidents within 24 hours. Three separate 24-hour clocks apply to incident reporting, confirmation of receipt and notification of preventive measures.

Finally, Government Decree No. 1024 allows the use of Russian-hosted cloud services for state systems provided the service meets or exceeds the required protection class, yet places full compliance responsibility on the heads of the user organizations. All three regulatory acts enter into force on 1 September 2026.

Related articles

Habr•Policy & Regulation

Building the Foundation of Digital Trust: Why Identity Security Remains Undervalued

Identity Security is presented as one of the most underestimated pillars of cybersecurity because granting access involves trusting individuals with sensitive information and systems. The article examines the deep intersection of IT and security functions, the costs of manual access errors, and the need to align business processes with technical controls. It references a 2026 Identity Conf study showing 43.5% of organizations experienced errors in manual rights assignment and 33.5% left access for former employees. Recommendations draw on NIST Human-Centered Cybersecurity concepts, SP 800-53, and Russian FSTEC Order No. 117 to design lifecycle processes covering account provisioning, privilege reviews, and continuous monitoring. Models such as RBAC and ABAC are discussed alongside IGA and IdM solutions to ensure business permissions map correctly to application rights. The piece stresses that successful projects require joint IT and security efforts from the initial survey through pilot and acceptance phases while measuring both risk reduction and operational efficiency.

AntiMalware•Policy & Regulation

VK Files Lawsuit in EU Court Seeking to Overturn Sanctions Imposed in July

Russian internet company VK has submitted a formal challenge to the European Union's sanctions regime by filing a case with the Court of Justice of the European Union. The company argues that the restrictions placed on VK and its subsidiary Communication Platform LLC are both unjustified and unlawful. The lawsuit, registered under case number T-664/26 on 7 October, directly contests the July sanctions that targeted the developer of the MAX messenger. Earlier restrictions had already led to the removal of multiple VK ecosystem applications from Apple App Store and Google Play, forcing users toward alternative distribution channels such as RuStore, Huawei AppGallery, Samsung Galaxy Store and Xiaomi GetApps. While installed Android applications continue to function and receive updates, iOS users face disrupted push notifications after the apps were delisted. The legal action itself does not automatically restore app availability in the affected stores.

Securitylab•Policy & Regulation

VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access

As of September 2026, Russia maintains no separate administrative fine for ordinary citizens simply connecting to a VPN service. Responsibility arises only for specific actions such as deliberately searching for known extremist materials, advertising tools to bypass restrictions, or failing to comply with Roskomnadzor demands as a service operator. Corporate VPNs used for remote access to company networks remain fully legal under exceptions in Article 15.8 of Law No. 149-FZ. New provisions in the Code of Administrative Offenses, including Articles 13.53, 13.52 and 14.3 introduced by Laws 281-FZ and 282-FZ, impose fines ranging from 3,000 to 500,000 rubles depending on the violation and the offender category. The rules distinguish clearly between end users, service owners and advertisers. VPN technology itself is not banned, yet public services face ongoing blocking and operators must integrate with state filtering systems. The material reflects the regulatory situation on 24 September 2026.

Habr•Policy & Regulation

Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators

A Moneta client outage traced back to erroneous filtering on Russia's TSPU system rather than internal infrastructure or DDoS protection. Engineers used curl, traceroute, nping, and custom Python scripts to confirm TCP payload-based blocking after the handshake. The team submitted a request via the VTS personal account, received partial acceptance status, then escalated to DCOA and SSOP to obtain the specific TSPU site number. Detailed network traces and active traffic were required for diagnostics. The case highlights coordination challenges between operators, DCOA, and SSOP when erroneous blocks occur on information resources.