+38 067 569 61 50

info@clapkey.com

List of Prohibited Software Grows to 1,564 Entries: What Changed and What IT Teams Should Do

The State Service of Special Communications (SSSCIP) has once again updated the List of software and communication (network) equipment prohibited for use. The new edition took effect on 21 July 2026: the list grew from 1,341 to 1,564 entries, i.e. 223 new items at once. For the public sector and critical infrastructure operators, this is not "just another sanctions news item" but a direct reason to check their own asset registers.

What this List is and where it came from

The creation of the List is provided for by Cabinet of Ministers Resolution No. 1335 of 22.10.2025. It is maintained by the Administration of the SSSCIP, specifically its Department of State Control in the Field of Information Protection and Cyber Defense. The document is published as open data on the service's official website in the "Activity" section.

Before the List appeared, the situation was typically Ukrainian: National Security and Defense Council (NSDC) sanctions decisions existed and were enacted by presidential decrees, but there was no single centralized source of "what exactly is prohibited". Because of this, some government bodies continued for years to operate sanctioned products, not out of intent but because there was no document to cite in tender documentation or in an internal audit report. The List closes this gap: it is the official centralized source for public authorities, local self-government bodies, military formations, state enterprises and critical infrastructure operators.

The update mechanics are simple: Department specialists process current and new NSDC decisions, analyze software products and communication equipment linked to sanctioned persons, and add them to the List. The document is dynamic by definition: it is constantly updated and supplemented.

Dynamics: from 27 entries to 1,564 in half a year

The most interesting part of this story is the pace. The July update was already the seventh since the beginning of 2026, and the List started with a few dozen entries. In half a year, the number of prohibited IT solutions has grown dozens of times over.

This means two things. First: a one-off infrastructure check "against the List" does not work: several weeks may pass between two editions, and what was merely undesirable yesterday has become formally prohibited today. Second: the reconciliation process must be put on a regular footing, preferably automated and tied to software inventory.

What was added this time

The 223 new items cover products and systems of several sanctioned vendors:

  1. LLC "Group of Companies 'Innotech'" — banking, fintech, corporate, analytical, integration, cloud and infrastructure software platforms. The broadest category by coverage: it includes both the application and the platform level.
  2. LLC "Truconf" — server and client software for videoconferencing, corporate communications and MCU servers. That is, not only workstation clients but also the server side of videoconferencing.
  3. LLC "Polyterm" — geoinformation software and software suites for modeling, calculation and dispatching of utility networks.
  4. The Zulu line — ZuluGIS/ZuluServer, ZuluNetTools, web and mobile components, OPC/API modules for heat, water supply, sewerage, gas and steam networks.
  5. Aviation and space — specialized software and information systems of FSBI "Aviamettelecom of Roshydromet" for aviation meteorological support, as well as software products of FSUE "Space Communications" and JSC "Amtel-Svyaz".

The Polyterm/Zulu block and the OPC modules deserve special attention. This is no longer office software but the level of industrial control systems (ICS) and dispatching of utility and energy networks, precisely the segment where a compromise causes not a data leak but a halt of the technological process. The presence of OPC/API components in this category means the ban also applies to "invisible" integration layers that usually nobody inventories because they have no icon in the Start menu.

What was already in the List before

The current edition, besides the new items, still contains the classics that are still found in Ukrainian organizations:

  1. accounting and corporate solutions based on 1C, BAS and UA-Budget;
  2. Kaspersky antivirus products;
  3. all services related to Yandex.

The Clapkey team has already written about this before:

- Ukraine tightens control over software products

- Who Really Owns BAS

The last item should be read more broadly than "don't visit the search engine": it also covers metrics and counters on websites, mapping APIs, and SDKs in mobile applications. Such things most often "hang" in the legacy code of websites and in old integrations.

Consequences of non-compliance

No sentimentality here. If prohibited software is found in the information systems of a state institution, it may become grounds for revoking the authorization of the comprehensive information protection system (CISP). Heads of the relevant organizations may be held administratively liable.

A revoked CISP authorization is not an abstract fine but an actual halt of the legitimate operation of the system with all its derivatives: from integration problems to issues during inspections and procurement.

The SSSCIP itself states the risk directly: using such products creates a threat of data leaks, unauthorized access to information resources, remote interference with system operation and shutdown of critically important processes.

A practical checklist for the IT team

What is worth doing without waiting for the next edition:

  1. Take a full software inventory. Not "from the admins' memory" but through real sources: WMI/registry inventory on Windows, package managers on Linux, monitoring system data, SCCM or equivalents, EDR reports. Prohibited software most often lives on "forgotten" servers.
  2. Separately go through the non-obvious. Libraries, drivers, plugins, OPC servers, SDKs in mobile applications, counters and maps on corporate websites, embedded components in ICS.
  3. Reconcile with the List's open data. Since it is published as open data, reconciliation can realistically be automated: parse the list into your own asset database (CMDB/NetBox/whatever) and put it on a weekly cron instead of comparing PDFs manually.
  4. Check procurement and contracts. The List was created, among other things, to simplify procurement and risk management processes. Tender documentation and existing support contracts are a separate front of work.
  5. Draw up a replacement plan with deadlines. For each item found: what we replace it with, who is responsible, the deadline, data migration risks. This will be especially painful for accounting systems on 1C/BAS and for industry-specific GIS.
  6. Document the result. An inventory report and a replacement plan are what you show during an inspection. Verbal confidence that "we don't have that" is not evidence.

Conclusion

The List has turned from a declarative document into a working control tool that changes almost monthly. The state's logic is clear: software is now considered not only a work tool but also a potential channel of cyberattack, with managed updates, telemetry and a channel to a vendor that is under sanctions.

For IT teams this means moving from one-off "clean-ups" to a permanent process: inventory → reconciliation with the current edition → replacement → documentation. Whoever builds this as a regular procedure now will not experience every next update as an emergency.

Sources:

  1. SSSCIP: "The List of software and communication equipment prohibited for use has been expanded to 1,564 entries" — cip.gov.ua
  2. SSSCIP: "List of software and communication (network) equipment prohibited for use" — cip.gov.ua

This page has been translated partially or fully using AI. Please send any translation feedback to info@clapkey.com.

#StandWithUkraine

Support the Armed Forces of Ukraine during the Russian invasion

Contacts

Office

4th floor, Metropolitan Mall (38 Gogol St.), Poltava, Ukraine, 36000