Compliance
Transition to “Kupina” Standard for Digital Signatures in Ukraine: What It Means for Businesses
Ukraine is switching to a new national cryptographic standard for qualified electronic signatures called “Kupina,” improving cybersecurity without requiring businesses to reissue existing certificates.
By NomadicTax Research Team • 5-8 min read • September 1, 2026
## What is the "Kupina" Standard?
The "Kupina" standard is Ukraine’s newly adopted national cryptographic algorithm for **qualified electronic signatures**. Starting September 1, 2026, this becomes the required standard for generating qualified certificates. ([tax.gov.ua](https://www.tax.gov.ua/en/mass-media/news/1045106.html?utm_source=openai))
## Key Details for Businesses and Individuals
- Existing certificates remain valid until their expiration—no need to reissue or replace them early. ([tax.gov.ua](https://www.tax.gov.ua/en/mass-media/news/1045106.html?utm_source=openai))
- The State Tax Service has been generating certificates under the “Kupina” standard since August 26, 2026, ensuring systems are ready in advance. ([tax.gov.ua](https://www.tax.gov.ua/en/mass-media/news/1045106.html?utm_source=openai))
- Systems remain compatible with both old and new standards in the transition period, so operations should be seamless. ([tax.gov.ua](https://www.tax.gov.ua/en/mass-media/news/1045106.html?utm_source=openai))
## Why the Shift?
- **Enhanced security:** The new standard is more resistant to modern cyber threats. It strengthens protection of signed documents and personal data. ([tax.gov.ua](https://www.tax.gov.ua/en/mass-media/news/1045106.html?utm_source=openai))
- **Future-proofing compliance:** The move aligns with best practices in cryptography, reducing vulnerabilities tied to outdated algorithms.
## What’s Useful for Tax & Legal Operations
- Digital filings, contract signing, declarations—all communications relying on qualified electronic signatures now fall under the “Kupina” standard. Offices using digital signatures should confirm all services (internal and external) accept this standard.
- Certificates issued under the old standards still hold legal validity until they expire, giving flexibility. But post-September 1, only “Kupina” for **new** certificates.
## Practical Steps for Businesses
1. **Check with your certificate provider** to see if they’ve upgraded to “Kupina” for new certificate issuance.
2. **Update internal policies** to ensure new signatures (from Sept 1 onward) comply with Kupina.
3. **Train staff and legal advisors** on using signatures, verifying validity, and recognizing old ones.
4. **Audit your digital signature usage**—contracts, tax submissions, government apps—to ensure compatibility.
## Example Scenarios
- **Example 1 – Contract signing**: A company signs a service contract digitally on September 2. If their certificate is newly issued, it must use the Kupina standard. If they sign with an old certificate (issued before its expiry), it’s still valid but businesses should choose Kupina for consistency.
- **Example 2 – Tax declarations**: When submitting declarations digitally after Sept 1, only newly issued signatures need to use the new algorithm. Existing tools/software should already work; if not, request updates.
## Conclusion
While the transition to the Kupina standard signifies improved cybersecurity, it's designed to be practical for businesses. No rush to replace existing keys—just plan now, ensure new signatures comply, and align processes ahead of the September 2026 change. This is a one-time technical update, not a whole new law or tax policy, but bears legal implications for digital compliance.