21-23 April, 2027Pavilion 3, Crocus Expo, Moscow
RU
Securika Expo
21-23 April, 2027Pavilion 3, Crocus Expo, Moscow
Securika Expo
17.06.20256 min read

IT And IS News: Changes In Legislation 2025.

The year 2025 was marked by significant changes in the legislation regulating the spheres of information technology (IT) and information security (IS) in Russia.

Lawmakers continue to adapt the regulatory framework to the new challenges of digital transformation, tightening requirements for businesses and increasing control over data processing, protection of critical infrastructure and import substitution. For B2B specialists, IT company managers, engineers and information security specialists, these changes are becoming decisive for strategic planning and operational activities.

 

This article presents a concentrated review of key legislative innovations that determine the vector of development of the IT and information security industry in Russia in 2025.

 

Key changes in legislation in the field of IT and information security


// Tightening regulation of critical information infrastructure (CII)


Amendments to Federal Law No. 187-FZ "On the Security of Critical Information Infrastructure of the Russian Federation" came into force on January 1, 2025. Key changes:

 

// expansion of the list of critical information infrastructure entities: now the number of obligated entities includes not only government and large commercial organizations, but also individual companies from the B2B segment providing services in the field of communications, transport, finance, and energy;
// updating the criteria for categorizing critical information infrastructure facilities: new parameters for assessing threats and vulnerabilities have been introduced, as well as requirements for mandatory security audits at least once every three years;
// increased liability: increased fines are provided for failure to comply with the requirements for the protection of critical information infrastructure, including administrative and criminal liability of officials.


// New rules for processing and cross-border transfer of personal data


In 2025, amendments to Federal Law No. 152-FZ "On Personal Data" came into force, which significantly affect the business processes of companies working with personal data:

 

// restriction of cross-border transfer: now companies are required to notify Roskomnadzor of their intention to transfer data abroad and obtain consent for transfer to countries that do not provide the necessary level of protection;
// tightening of requirements for consents: consent forms should be more detailed, and storage of consents should be ensured using electronic signatures;
// Mandatory appointment of a DPO: For organisations processing large volumes of personal data or special categories of data, the obligation to appoint a Data Protection Officer has been introduced.


// Import substitution in IT and information security: new requirements for software


As part of the policy of technological sovereignty, requirements for the use of domestic software have been tightened since 2025:

 

// state software registry: the list of activities for which the use of software from the register of domestic programs is mandatory has been expanded;
// certification of information security tools: all new information security solutions implemented in the critical information infrastructure must undergo mandatory certification by the FSTEC of Russia;
// transition period: for a number of industries, a transition period has been established until the end of 2025, after which the use of foreign solutions will be possible only with the consent of the relevant departments.


// New standards and requirements for information security incident management


In 2025, new state standards for information security incident management were approved (GOST R 58900-2025):

 

// mandatory implementation of ISMS: a requirement for the implementation of information security management systems (ISMS) has been introduced for all critical information infrastructure entities and large organizations;
// Incident logging: requirements have been introduced for the mandatory maintenance of electronic incident logs and their storage for at least 5 years;
// notification periods: the mandatory notification periods for regulators and affected persons about incidents that have occurred have been reduced to 24 hours from the moment of detection.


// Introduction of liability for the use of uncertified protective equipment


Since 2025, amendments to the Code of Administrative Offenses of the Russian Federation have come into force, increasing liability for the use of uncertified information security tools:

 

// administrative fines: for legal entities - up to 5 million rubles, for officials - up to 500 thousand rubles;
// Mandatory confiscation of uncertified means: by court order, it is possible to confiscate and destroy uncertified solutions used in the critical information infrastructure.


Practical recommendations for business


In the context of new legislative requirements, B2B companies are advised to:

 

// conduct an audit of compliance with new requirements: especially in terms of processing personal data and protecting critical information infrastructure;
// appoint responsible persons: for information security and personal data protection (DPO), ensure their training;
// update internal policies and procedures to comply with new standards and requirements;
// re-equip the infrastructure: switch to certified domestic solutions, especially for the protection of critical information infrastructure;
// implement an information security management system and incident monitoring systems: automate the processes of detecting and responding to incidents.


Trends in the development of the IT and information security industry


// Growing role of domestic developers


As a result of the import substitution policy, there has been a significant increase in demand for domestic solutions in the field of information security and IT, as well as the active development of the ecosystem of Russian vendors.

 

// Strengthening state control


Regulators are receiving additional powers to monitor the activities of companies in IT and information security, including conducting unscheduled inspections and compliance audits.

 

// Digital Transformation and New Threats


With the development of the digital economy and the introduction of new technologies (AI, IoT, cloud services), the number and complexity of cyber threats increases, which requires companies to constantly improve their security systems.

 

Conclusion


2025 has become a turning point for Russian legislation in the field of IT and information security. New requirements tighten business responsibility for information protection, stimulate the transition to domestic solutions and require continuous improvement of security management processes. It is important for B2B specialists to promptly respond to changes, integrate new standards and technologies, and build a systematic approach to risk management.

 

Present technologies and innovative solutions in the field of information security at the Securika Moscow 2026 exhibition, which will be held from April 22 to 24 at the Crocus Expo IEC, Pavilion 3.


FIND OUT THE TERMS OF PARTICIPATION

Securika Expo