2025-05-20 | 17/21/2298/К03

Added · Updated

Decision on Approving the Procedure for the Use of Electronic Signatures by Capital Market Participants and Professional Organized Commodity Market Participants

The National Commission for Securities and Stock Market approves a procedure governing the use of electronic signatures and electronic seals by capital market participants and professional organized commodity market participants. During martial law and for six months thereafter, the use of electronic signatures based on open key certificates issued by qualified trust service providers is permitted even if the private key is not stored in a qualified signature device, excluding notarized transactions and high-risk scenarios. Market participants must align their activities with these requirements within twelve months of the decision's entry into force, while the approved procedure itself takes effect six months after official publication.

National Securities and Stock Market Commission logo

Ukraine

National Securities and Stock Market Commission

Click to view thumbnail

NATIONAL COMMISSION FOR SECURITIES AND STOCK MARKET DECISION Kyiv On Approval of the Procedure for the Use of Electronic Signatures by Participants of Capital Markets and Professional Participants of Organized Commodity Markets

In accordance with subparagraphs 1 and 105 of Part One of Article 7, Article 30 of the Law of Ukraine "On State Regulation of Capital Markets and Organized Commodity Markets", Article 6 of the Law of Ukraine "On Electronic Documents and Electronic Document Management", with the aim of defining the procedure for the use of electronic signatures and electronic seals during the creation, processing, and storage of electronic documents by participants of capital markets and professional participants of organized commodity markets,

The National Commission for Securities and Stock Market HAS DECIDED:

  1. Approve the Procedure for the Use of Electronic Signatures by Participants of Capital Markets and Professional Participants of Organized Commodity Markets, attached hereto.

  2. Establish that during the period of martial law on the territory of Ukraine and for six months from the day of its termination or cancellation, the use of electronic signatures or seals based on open key certificates issued by qualified providers of electronic trust services is permitted, without information that the private key is stored in a means of a qualified electronic signature or seal, by users of electronic trust services for the purpose of electronic interaction, electronic identification, and authentication of physical and legal persons and representatives of legal persons in cases where Ukrainian legislation provides for the use exclusively of qualified electronic signatures or seals (means of qualified electronic signature or seal) or means of electronic identification with a high level of trust, except for performing legal transactions in electronic form that are subject to notarial certification and/or state registration in cases established by the laws of Ukraine, and in cases related to high risk for information security, determined by the owners of the respective information and information-communication systems, taking into account the restrictions established in Article 17 of the Law of Ukraine "On Electronic Identification and Electronic Trust Services".

  3. Participants of capital markets and professional participants of organized commodity markets shall bring their activities into compliance with the requirements of the Procedure for the Use of Electronic Signatures by Participants of Capital Markets and Professional Participants of Organized Commodity Markets approved by this decision within twelve months from the day this decision enters into force.

  4. The Department of Information Technologies shall ensure the submission of this decision for state registration to the Ministry of Justice of Ukraine.

  5. The Administration of Administrative Activities shall ensure the publication of this decision on the official website of the National Commission for Securities and Stock Market.

  6. The Department of Legal Support and Internal Compliance Control, after state registration with the Ministry of Justice of Ukraine, shall ensure the publication of this decision on the official website of the National Commission for Securities and Stock Market.

  7. This decision enters into force from the day following the day of its official publication, except for paragraph 1 of this decision, which enters into force six months from the day of its official publication.

  8. Control over the implementation of this decision shall be entrusted to a member of the National Commission for Securities and Stock Market, Yu. Shapoval.

Chairman of the Commission Ruslan MAGOMEDOV Protocol of the Commission meeting of 20.05.2025 No. 59

APPROVED by the decision of the National Commission for Securities and Stock Market of ___ _________2025 No. ___

Procedure for the Use of Electronic Signatures by Participants of Capital Markets and Professional Participants of Organized Commodity Markets

I. General Provisions

  1. This Procedure is developed in accordance with the Laws of Ukraine "On State Regulation of Capital Markets and Organized Commodity Markets", "On Capital Markets and Organized Commodity Markets", "On Electronic Documents and Electronic Document Management", "On Electronic Identification and Electronic Trust Services" (hereinafter – the Law) and defines the procedure for the use of electronic signatures (hereinafter – ES) and electronic seals during the creation, processing, and storage of electronic documents by participants of capital markets and professional participants of organized commodity markets (hereinafter – market participants) in their electronic interaction.

The requirements of this Procedure apply exclusively to cases of use by market participants of types of ES and electronic seals defined in paragraph 14 of Section II of this Procedure.

The requirements of this Procedure do not apply to the electronic interaction of market participants with the National Bank of Ukraine in accordance with the regulatory legal acts of the National Bank of Ukraine.

This Procedure does not apply to the implementation of electronic identification in systems where official information and information containing state secrets are processed.

  1. In this Procedure, terms are used in the following meanings:
  1. verification – measures taken by a market participant for the purpose of checking (confirming) the belonging of identification data received by the market participant to the respective person;

  2. open network service – a mobile application, web service, or other software that allows exchanging messages between electronic devices of market participants and users through public electronic communication networks;

  3. electronic touch device – an electronic device with a touch screen on which a person can create a digital handwritten signature;

  4. identification – measures taken by a market participant to establish a person's identity by obtaining their identification data;

  5. client – a client of a market participant, a user of services provided on capital markets and organized commodity markets;

  6. counterparty – any legal or natural person who has relations with a market participant related to activities on capital markets and organized commodity markets;

  7. integrity check of an electronic document – a procedure carried out by confirming an advanced or qualified ES or seal in accordance with legislation, and in the case of applying an ES or seal of another type to an electronic document – by using other means and methods of information protection, complying with the requirements of legislation in the field of information protection, which allow detecting any changes in the electronic document after signing;

  8. simple electronic signature (hereinafter – simple ES) – any type of ES, except for a qualified ES, digital handwritten signature (hereinafter – DHS), advanced ES (hereinafter – AES), AES based on a qualified certificate;

  9. subject of electronic interaction – a market participant, a client, or a counterparty of such a market participant;

  10. advanced electronic seal based on a qualified electronic seal certificate (hereinafter – electronic seal with a qualified certificate) – an advanced electronic seal created using a qualified electronic seal certificate, which contains a mark that this certificate was formed as qualified for the use of an electronic seal, and there is no information that the private key is stored in a means of a qualified electronic signature or seal;

  11. AES based on a qualified electronic signature certificate (hereinafter – AES with a qualified certificate) – an AES created using a qualified electronic signature certificate, in which there is no information that the private key is stored in a means of a qualified electronic signature or seal;

  12. authorized person – a person who is not an employee of a market participant, who has been granted authority to sign contracts and other documents on behalf of the market participant with clients and counterparties of the market participant in accordance with a power of attorney and/or based on legal transactions;

  13. authorized representative – an employee of a market participant, whose authority according to internal documents or based on a power of attorney includes signing contracts and other documents on behalf of the market participant with clients and counterparties of the market participant;

  14. digital handwritten signature (DHS) – an electronic signature that is a handwritten signature of a natural person, created on the screen of an electronic touch device.

Other terms in this Procedure are used in the meanings provided in the Law, the Laws of Ukraine "On State Regulation of Capital Markets and Organized Commodity Markets", "On Capital Markets and Organized Commodity Markets", "On Electronic Documents and Electronic Document Management", "On Electronic Commerce", and other laws of Ukraine and regulatory legal acts of the NSSMC.

  1. The head of a market participant is responsible for organizing the use of ES and electronic seals in the market participant, as well as for the use of ES and electronic seals by this market participant, and for the use of ES and electronic seals by authorized representatives / authorized persons of the market participant during their interaction on behalf of the market participant with clients and counterparties of the market participant, unless otherwise established by Ukrainian legislation.

  2. ES is a mandatory attribute of an electronic document.

  3. The requirements of this Procedure regarding the use of ES cannot be interpreted by subjects of electronic interaction as restricting the rights of subjects of electronic interaction to perform legal transactions in the form of paper documents (changing, supplementing, or terminating the action of electronic documents with paper documents or in another form not prohibited by Ukrainian legislation and vice versa) or in oral form, unless the law establishes an obligation to perform legal transactions in written form.

  4. A market participant is obliged to ensure the possibility of checking the integrity and authenticity of electronic documents created using the technology defined by the market participant. The burden of proving the integrity and authenticity of electronic documents created using the technology defined by the market participant lies with the market participant (regardless of the technological capabilities and competencies of the personnel).

  5. A person who signed an electronic document with an ES, in this way, certifies that they have familiarized themselves with the entire text of the document, fully understood its content, have no objections to the text of the document (or their objections are included as a separate attribute of the document), and consciously used their ES in the context provided by the document (signed, approved, agreed, reviewed, certified, familiarized).

  6. An electronic document is created in the sequence defined by the applied information processing technology, if the electronic document is signed by two or more persons. The information processing technology is developed taking into account Ukrainian legislation and may be defined in the internal documents of the market participant and/or in a contract concluded between the market participant and its client, counterparty, or commercial agent. The creation of an electronic document is completed by applying the last ES in accordance with the technology for creating such an electronic document.

  7. A market participant is obliged to develop, taking into account the requirements of Ukrainian legislation, internal documents in which the following procedure must be established:

  1. creation and certification of an electronic copy of a paper document;
  2. creation and certification of a paper copy of an electronic document;
  3. detection of any changes in an electronic document, in an electronic copy of a paper document;
  4. use of ES and electronic seals of the market participant;
  5. detection of any changes in an electronic document, in an electronic copy of a paper document after the use of an electronic seal.

The procedures specified in subparagraphs 1-5 of this paragraph must describe the use of those types of ES and electronic seals used by the market participant.

The internal documents specified in this paragraph are mandatory for all employees of the market participant and authorized representatives of the market participant to comply with and may be оформлені as separate documents, one document, or be part(s) of another document(s).

A market participant is obliged to ensure unimpeded access for clients and potential clients of the market participant to the documents specified in this paragraph (in part concerning the electronic interaction of the market participant and clients) by placing these documents or excerpts from them on the official websites of the market participant, including their mobile versions, in the mobile application and/or in the premises of the market participant and its separate subdivisions.

A bank has the right to perform the requirements defined by this paragraph by extending the action of the bank's internal documents developed in compliance with the requirements of the National Bank of Ukraine to cases of use of ES in conducting professional activities on capital markets, provided that other requirements of this Procedure are met.

  1. A market participant is obliged, taking into account the requirements of Ukrainian legislation in the field of information protection, information security, and cyber defense, to develop internal documents that establish requirements for granting, revoking, and controlling access to the information systems of the market participant used for receiving, registering, processing, storing, and sending electronic documents, and which must contain:
  1. requirements for identification, authentication, and authorization of clients of the market participant;
  2. sequence of actions during access management, sequence of actions during remote access management (registration, granting authority, viewing, and revoking access);
  3. list of typical functions and access rights to the information systems of the market participant;
  4. requirements for carrying out access control measures;
  5. periodicity of control over granted access rights;
  6. requirements for logging actions during access management.

A market participant is obliged to ensure compliance with the principle of granting the minimum level of authority when providing access to the information systems of the market participant used for receiving, registering, processing, storing, and sending electronic documents.

The internal documents developed specified in paragraph 10 of this section are mandatory for all employees and authorized representatives of the market participant to comply with and may be оформлені as separate documents, one document, or be part(s) of another document(s).

  1. In addition to the requirements established by internal documents, the list of which is specified in subparagraphs 1-6 of paragraph 10 of this section, a market participant is obliged to ensure compliance with requirements for ensuring information security in information systems used for receiving, registering, processing, storing, and sending electronic documents, taking into account the requirements of the Law of Ukraine "On Protection of Information in Information and Communication Systems".

  2. ES (except for qualified ES and seal or advanced ES and seal) has legal force regardless of the technologies used for creating the ES, if it meets the following conditions:

  1. electronic data used for creating the ES are unique and unambiguously linked to the signer and not linked to any other person;
  2. ES allows unambiguous identification of the signer;
  3. the technology of using ES ensures the signer control over the electronic data being signed and the electronic data used for creating the ES during signing;
  4. during verification in accordance with the procedure approved in the institution, no changes in the electronic document were detected;
  5. during verification in accordance with the procedure approved in the institution, no changes in the ES after signing the electronic document were detected.
  1. The NSSMC has the right to check the compliance of a market participant with the requirements of this Procedure, as well as to carry out inspections of information-communication systems used by market participants to prove the integrity and authenticity of electronic documents.

II. Types of Electronic Signature and Electronic Seal

  1. During the creation, processing, and storage of electronic documents by market participants, the following are used in cases defined by legislation:
  1. qualified ES (hereinafter – QES);

  2. DHS;

  3. AES with a qualified certificate;

  4. AES;

  5. simple ES;

  6. qualified electronic seal;

  7. advanced electronic seal with a qualified certificate;

  8. advanced electronic seal.

  1. The use of AES, advanced electronic seal, and simple ES is carried out on the basis of a contract between the market participant and the client / counterparty of the market participant or the market participant and a person intending to become a client / counterparty. The contract is concluded in written form after carrying out identification and verification in accordance with the requirements of Ukrainian legislation of the client / counterparty of the market participant or the person intending to become a client / counterparty:
  1. in the form of a paper document with handwritten signatures of the parties, or
  2. as an electronic document with QES of the parties, or
  3. as an electronic document with AES with a qualified certificate of the client / counterparty of the market participant and QES of the authorized representative of the market participant, or
  4. as an electronic document with DHS of a natural person defined in paragraph 28 of Section IV of this Procedure, and QES of the authorized representative of the market participant, complying with the requirements of Section IV of this Procedure regarding the use of DHS, or
  5. as an electronic document using any types of ES, regarding which a contract has already been concluded between the client / counterparty of the market participant and the market participant in accordance with the requirements of one of subparagraphs 1 – 4 of paragraph 16 of this Section II.

A contract on the use of AES, advanced electronic seal, and simple ES must contain conditions and procedure (process) for recognition by the market participant and client / counterparty of legal transactions in the form of electronic documents using AES, advanced electronic seal, or simple ES, respectively.

The contract must also contain conditions regarding the distribution of risks of losses that may be caused to signers and third parties in the event of the use of simple ES, AES, or advanced electronic seal, respectively.

Conclusion of a separate contract regarding the use by a client of a market participant of QES, DHS, AES with a qualified certificate, qualified electronic seal, electronic seal with a qualified certificate is not required provided that the requirements of this Procedure are met.

A bank may fulfill the requirements specified in this paragraph by including relevant provisions in the contract concluded between the bank and the client/counterparty. In such a case, additional fulfillment of the requirements of this paragraph by including relevant provisions in contracts concluded by the bank exclusively within the framework of conducting professional activities on capital markets is not mandatory.

  1. A market participant is obliged, after creating an electronic document, to send a copy of this electronic document with all necessary attributes to the email address specified by the client / counterparty of the market participant or provide the electronic document in another manner agreed with the client / counterparty.

A market participant is obliged to provide the client / counterparty with a certified paper copy of the electronic document upon their request.

  1. A market participant independently makes a decision on the use of a particular type of ES and electronic seal, complying with the requirements of Ukrainian legislation on electronic trust services, electronic document management, this Procedure, and regulatory legal acts of the NSSMC.

  2. A market participant carries out the receiving, processing, storing, and sending of electronic documents and information necessary for creating electronic documents, complying with the requirements of Ukrainian legislation on the protection of information with limited access, including: personal data, professional secrecy, and commercial secrecy.

  3. A market participant / commercial agent of a market participant has the right to use open network services for receiving / providing / sending information that may be classified as information with limited access, defined in paragraph 18 of this section, if the following requirements are met simultaneously:

  1. electronic interaction is carried out exclusively between the market participant and the client / counterparty;
  2. the market participant has previously obtained written consent from the client/counterparty of the market participant to carry out such actions or the contract with the client / counterparty contains such consent from the client / counterparty;
  3. the market participant ensures compliance with the requirements of Ukrainian legislation in the field of information protection, information security, and cyber defense.

A market participant determines in its own internal documents the technology for using open network services for receiving / providing information defined in paragraph 18 of this section and, in case of violation of the requirements of Ukrainian legislation, bears responsibility for damage caused to the client / counterparty of the market participant during the use of the technology introduced by the market participant.

A market participant proves the fact of voluntary transfer of information defined in paragraph 18 of this section by the client / counterparty of the market participant in case of denial by them of the fact of voluntary transfer of such information.

  1. An authorized representative of a market participant, when interacting with a client / counterparty in the case of creating electronic copies of paper documents, uses the QES of the authorized representative of the market participant and/or the qualified electronic seal of the market participant, and/or the advanced

8 Qualified Electronic Seal based on a qualified certificate with a qualified electronic time stamp. 21. The creation of electronic documents for permanent and long-term (more than 10 years) storage is carried out using the QES of an authorized person according to the constituent documents of the market participant / authorized representative of the market participant and/or the qualified electronic seal of the market participant, which ensure the possibility of checking the corresponding QES and/or qualified electronic seal over a long-term period in accordance with the requirements of standards that define the requirements for the creation of qualified electronic signatures and qualified electronic seals in the event of the creation of electronic documents that, in accordance with the legislation of Ukraine, are subject to transfer for archival storage, listed in the appendix to this Procedure. 22. An authorized person according to the constituent documents of the market participant / authorized representative of the market participant – a legal entity for applying QES and AES with a qualified certificate is obliged to use a qualified public key certificate that contains the code of the legal entity in the Unified State Register of Enterprises and Organizations of Ukraine (hereinafter – identification code of the legal entity), the representative of which he/she is. A natural person acting on behalf of a legal entity – a client/counterparty of the market participant (hereinafter – representative of the client/counterparty), for applying QES and AES with a qualified certificate, has the right to use a qualified public key certificate that meets one of the following requirements:

  1. the qualified public key certificate of the representative of the client/counterparty contains the identification code of the legal entity;
  2. the qualified public key certificate of the representative of the client/counterparty does not contain the identification code of the legal entity and the QES/AES applied by the representative of the client/counterparty with a qualified certificate is certified by the qualified electronic seal of the legal entity – the client/counterparty;
  3. the qualified public key certificate of the representative of the client/counterparty does not contain the identification code of the legal entity and the market participant has all the necessary documents confirming the authority of the representative of the client/counterparty to sign the corresponding document on behalf of the legal entity – the client/counterparty.
  1. An electronic interaction subject – a legal entity, the representative of which uses a qualified public key certificate containing the identification code of this legal entity, is obliged to ensure the submission of an application for cancellation of the qualified public key certificate of the representative of the legal entity to the qualified provider of electronic trust services in the event of the occurrence of one of the following events:

9

  1. changes in the data entered in the qualified public key certificate of the representative of the legal entity;
  2. dismissal of an employee of the legal entity;
  3. termination of the representation of the legal entity. Until the cancellation of the qualified public key certificate of the representative of the legal entity by the qualified provider of electronic trust services, it is considered that the authority of such representative in relations with third parties has not been cancelled, and actions performed by such representative are considered to be performed by the electronic interaction subject. III. Use of QES
  1. The market participant is obliged to ensure:
  1. acceptance, registration, confirmation of receipt of electronic documents with applied QES in compliance with the requirements of the legislation of Ukraine in the field of electronic document management;
  2. functioning of an electronic mailbox for acceptance, registration, confirmation of receipt of electronic documents with applied QES of clients/counterparties, except in cases where electronic interaction according to the terms of contracts concluded with clients/counterparties must be carried out exclusively in a defined information system between them. The market participant has the right to define additional channels of electronic interaction through which it ensures acceptance, registration, confirmation of receipt of electronic documents with applied QES, and to ensure free access of clients/counterparties and potential clients/counterparties to information about the specified channels of electronic interaction.
  1. Verification and confirmation of QES is carried out in accordance with the requirements of the Law.
  2. The qualified public key certificate must meet the requirements of the Law.
  3. The signatory is obliged to use a qualified electronic time stamp when signing an electronic document with QES, and the corresponding electronic interaction system must ensure the verification of the presence of a qualified electronic time stamp. The signatory is obliged to check the validity of his/her qualified public key certificate of the signatory before applying QES. Verification of the validity of the qualified public key certificate of the signatory is carried out in accordance with the requirements of the Law. The signatory is prohibited from signing an electronic document if the qualified public key certificate of the signatory is invalid or if it is impossible to obtain information about its status.

10 IV. Use of QES (Qualified Electronic Signature) 28. The requirements of this section apply to market participants and their clients for signing electronic documents. 29. The requirements of this section of the Procedure apply exclusively in the event of the physical presence of clients in the premises of the market participant or institutions acting on behalf of this market participant for concluding/signing contracts and other documents that are оформляються (drawn up) for the implementation of operations. 30. A natural person who is a client of the market participant or intends to become a client of the market participant has the right to use QES for signing electronic documents during electronic interaction exclusively with the market participant/commercial agent of the market participant in compliance with the requirements of this Procedure. A natural person who is a representative of a natural person who is a client of the market participant or intends to become a client of the market participant has the right to use QES for signing electronic documents during electronic interaction exclusively with the market participant/commercial agent of the market participant in compliance with the requirements of this Procedure and exclusively in cases established by regulatory legal acts of the NCSPFU. 31. The market participant independently determines the technology for creating electronic documents with QES and ensures compliance with the requirements of this Procedure. The market participant is obliged to ensure compliance with the following requirements during the creation of an electronic document with QES of the signatory:

  1. identification and verification of the signatory in accordance with the requirements of the legislation of Ukraine;
  2. familiarization of the signatory with the text of the document before signing it with QES;
  3. signing with QES exactly that document with which the signatory was familiarized;
  4. inseparable combination of QES with the electronic document signed by this QES;
  5. automatic creation of a qualified electronic time stamp for the electronic document immediately after its signing with QES;
  6. carrying out verification of the QES of the signatory for its correspondence to the sample of the handwritten signature in the signatory's passport or in another document containing the signature of the person/digital signature of the person and certifying the identity of the signatory and which, in accordance with the legislation of Ukraine, can be used on the territory of Ukraine for making legal transactions, or in the card of signature samples – in cases defined by regulatory legal acts of the National Bank. If the QES of the signatory does not correspond to the sample of the handwritten signature in the signatory's passport or in another document containing the signature of the person/digital signature of the person, and certifying the identity of the signatory and which, in accordance with the legislation of Ukraine, can be used on the territory of Ukraine for making

11 legal transactions, the authorized representative of the market participant is obliged to terminate the procedure for creating an electronic document with QES of the signatory; 7) signing of the electronic document by the authorized representative of the market participant using QES with a qualified electronic time stamp and/or certification of the electronic document by the qualified electronic seal of the market participant with a qualified electronic time stamp; 8) recording of actions of the signatory and authorized representatives of the market participant related to the creation of electronic documents with QES in an electronic event log protected from modification and destruction; 9) confidentiality of all data transmitted between the electronic sensor device and the information system of the market participant. The market participant has the right not to apply sub-items 1 and 6 of this paragraph if the legislation does not establish an obligation to identify/verify the signatory. 32. The market participant, after creating an electronic document with QES, is obliged to ensure the protection of this QES from further destruction, copying, distribution, and modification. 33. The market participant is obliged to ensure the application of antivirus protection in the information system of the market participant and on the device to which the electronic sensor device used for creating QES is connected. 34. The list of events recorded in the electronic event log is determined by the market participant taking into account the possibility of subsequently:

  1. confirming the fact, date, and time of signing the document with QES by the person specified in paragraph 30 of this section, and the authorized representative of the market participant;
  2. confirming the fact of prior familiarization of the signatory with the text of the document that was signed;
  3. providing information regarding the process of signing a specific document and proving the reliability of such information at the request of authorized state bodies in cases established by the laws of Ukraine, or by court decision.
  1. The market participant has the right to apply photo and/or video recording procedures, other procedures for the purpose of documenting and controlling the process of signing a document by a client using QES. The application of the specified procedures must be carried out subject to the prior consent of the client. The market participant has no right to use for other purposes or transfer to other persons information obtained during the procedure of documenting the process of signing a document by the signatory with QES without the consent of the client, except in cases provided for by the laws of Ukraine.

12 36. The market participant is obliged to store information recorded during the process of creating an electronic document with QES until the expiration of the storage period of the electronic document with which the specified information is associated, in accordance with the requirements of the legislation of Ukraine. 37. The market participant ensures proving the integrity of the electronic document and the authorship of the QES of the signatory in the event of the signatory denying the fact of signing the electronic document or contesting certain parts of the electronic document. 38. The market participant bears responsibility for damage caused to the signatory as a result of such market participant's violation of the requirements of the legislation of Ukraine regarding the technology for creating an electronic document with QES. 39. Disputed issues regarding documents signed with QES are resolved between the market participant and the signatory in the order established by the legislation of Ukraine. 40. The authorized representative of the market participant has no right to use QES for signing electronic documents on behalf of the market participant. V. Use of AES with Qualified Certificate 41. Electronic interaction subjects have the right to use AES with a qualified certificate in cases where such right is established by the laws of Ukraine or regulatory legal acts of the NCSPFU. Electronic interaction subjects do not have the right to use AES with a qualified certificate in the event of fulfillment of at least one of the following conditions:

  1. AES with a qualified certificate is not included in the list of ES that can be used for signing electronic documents in accordance with the requirements of regulatory legal acts of the NCSPFU;
  2. according to the requirements of the legislation, the corresponding document must be created in the form of a paper document and contain the handwritten signature of the person.
  1. Electronic interaction subjects for using AES with a qualified certificate are obliged to obtain from the qualified provider of electronic trust services a qualified electronic trust service for the formation, verification, and confirmation of the validity of the qualified certificate of the electronic signature or seal.
  2. The market participant determines the possibility of using AES with a qualified certificate based on the results of risk assessment of using this type of ES, except in cases where the legislation of Ukraine establishes an obligation or right for electronic interaction subjects to use AES with a qualified certificate. The market participant using AES with a qualified certificate is obliged to ensure:
  1. notification of its client, counterparty about the possibility of using AES with a qualified certificate;
  2. acceptance, registration, confirmation of receipt of electronic documents with applied AES with a qualified certificate in compliance with the requirements of the legislation of Ukraine in the field of electronic document management;
  3. functioning of an electronic mailbox for acceptance, registration, confirmation of receipt of electronic documents with applied AES with a qualified certificate of clients/counterparties, except in cases where electronic interaction according to the terms of contracts concluded with clients/counterparties must be carried out exclusively in a defined information system between them. The market participant has the right to define additional channels of electronic interaction through which it ensures acceptance, registration, confirmation of receipt of electronic documents with applied AES with a qualified certificate, and to ensure free access of clients/counterparties and potential clients/counterparties to information about the specified channels of electronic interaction.
  1. Verification and confirmation of AES with a qualified certificate are carried out within the framework of obtaining a qualified electronic trust service for the creation, verification, and confirmation of the validity of the qualified electronic signature or seal. In the process of confirming AES with a qualified certificate, the validity of such signature is confirmed in the event of fulfillment of all of the following conditions:
  1. use for the creation of AES with a qualified certificate of a qualified public key certificate of the signatory that meets the requirements established by the Law;
  2. issuance of the qualified public key certificate of the signatory by the qualified provider of electronic trust services and its validity at the moment of creation of AES with a qualified certificate;
  3. correspondence of the value of the public key to its value contained in the qualified public key certificate of the signatory;
  4. correct entry of the unique set of data determining the signatory into the qualified public key certificate of the signatory;
  5. indication in the qualified public key certificate of the signatory about the use of a pseudonym in it (in the event of its use by the person at the moment of creation of AES with a qualified certificate);
  6. integrity of electronic data associated with this AES with a qualified certificate is not violated;
  7. compliance with the requirements established by the Law.

13 45. The qualified public key certificate used for the creation of AES with a qualified certificate must meet the requirements of the Law. 46. The signatory is obliged to use a qualified electronic time stamp when signing an electronic document with AES with a qualified certificate. The signatory is obliged to check the validity of his/her qualified public key certificate of the signatory during the application of AES with a qualified certificate. Verification of the validity of the qualified public key certificate is carried out in accordance with the requirements of the Law. The signatory is prohibited from applying AES with a qualified certificate if the qualified public key certificate of the signatory is invalid or if it is impossible to obtain information about its status. VI. Use of AES 47. Market participants and their counterparties and clients in the course of making legal transactions in the form of electronic documents have the right to use AES on the basis of a contract taking into account the requirements of paragraph 15 of Section II of this Procedure. 48. The market participant determines the technology for using AES and the means of advanced electronic signature or seal used during interaction with the client/counterparty. 49. Electronic interaction subjects use AES without a public key certificate or the validity of the public key of the signatory is certified by a public key certificate on a contractual basis, or the validity of the public key of the signatory is certified by the provider of electronic trust services in accordance with the requirements of regulatory legal acts in the field of electronic trust services. 50. AES is considered to have passed verification if all of the following requirements are met:

  1. verification of AES is carried out in accordance with the procedure specified in the contract concluded between electronic interaction subjects;
  2. AES meets the requirements defined by the Law. VII. Use of Simple ES
  1. The client, counterparty of the market participant has the right to use simple ES in the event of compliance with the following requirements:
  1. electronic interaction is carried out exclusively with this market participant and using the technology defined by the market participant;

14 2) the use of simple ES is carried out on the basis of a contract in accordance with the requirements of paragraph 16 of Section II of this Procedure. 52. Simple ES must ensure unambiguous identification of the signatory's person, in accordance with the legislation. 53. Proving the integrity of electronic documents with applied simple ES can be ensured by the means of the information system in which the creation, processing, and storage of electronic documents are carried out. 54. The market participant ensures proving the integrity, reliability, and authorship of the electronic document with applied simple ES. The market participant, in the event of non-compliance with the specified requirement, bears responsibility for damage caused to the client of the market participant. VIII. Use of Qualified Electronic Seal 55. The electronic interaction subject is obliged to use the qualified electronic seal in cases defined by the legislation of Ukraine. 56. Qualified electronic seal is used if, in accordance with the legislation of Ukraine:

  1. it is necessary to ensure the reliability of the origin of related electronic data, to certify the validity of the electronic signature on the electronic document;
  2. affixing a seal is required to certify the correspondence of copies of documents to the originals;
  3. it is necessary to confirm the authority of the representative of the legal entity to use ES in the context provided by the document (signing, approval, agreement, visa, certification, familiarization).
  1. Application of qualified electronic seals to electronic documents is carried out by an employee of the electronic interaction subject who has the authority to do so. The market participant is obliged to approve by an internal document the list of its employees who are granted the right to use qualified electronic seals for electronic documents (in the event of using qualified electronic seals).
  2. The electronic interaction subject has the right to use the qualified electronic seal in the event of providing or receiving services in electronic form or during the implementation of information exchange with other electronic interaction subjects. The electronic interaction subject, whose constituent documents do not provide for the presence of a physical seal, has the right to use the qualified electronic seal for the purpose of confirming the integrity and origin of information during information interaction.
  3. The qualified certificate of the electronic seal must meet the requirements of the Law and have a mark that this certificate was formed as qualified for the use of the electronic seal.
  4. Verification and confirmation of the qualified electronic seal are carried out in accordance with the requirements of the Law.
  5. The electronic interaction subject has the right to use more than one qualified electronic seal.
  6. The electronic interaction subject is obliged to ensure the use of a qualified electronic time stamp in the event of application of the qualified electronic seal, as defined in paragraph 56 of this section. The electronic interaction subject is obliged to check the validity of the qualified certificate of the electronic seal during the application of the qualified electronic seal. Verification of the validity of the qualified certificate of the electronic seal is carried out in accordance with the requirements of the Law. The electronic interaction subject is prohibited from applying the qualified electronic seal if the qualified certificate of the electronic seal is invalid or if it is impossible to obtain information about its status. IX. Use of Electronic Seal with Qualified Certificate
  7. Electronic interaction subjects have the right to use the electronic seal with a qualified certificate in cases where the legislation of Ukraine does not provide for an obligation for electronic interaction subjects to use exclusively the qualified electronic seal. Electronic interaction subjects use the electronic seal with a qualified certificate in cases where the legislation of Ukraine establishes an obligation for electronic interaction subjects to use the electronic seal with a qualified certificate.
  8. Electronic interaction subjects for using the electronic seal with a qualified certificate are obliged to obtain from the qualified provider of electronic trust services a qualified electronic trust service for the formation, verification, and confirmation of the validity of the qualified certificate of the electronic signature or seal.

17

  1. A qualified electronic seal is used if Ukrainian legislation provides for:
  1. the presence of a seal with a qualified certificate on electronic documents;
  2. the application of a seal to certify the correspondence of copies of documents to originals using a qualified electronic seal;
  3. the use of a qualified electronic seal to confirm the authority of a representative of a legal entity to use an ES in the context defined by the document (signing, approval, agreement, visa, certification, familiarization).
  1. The application of qualified electronic seals to electronic documents is carried out by an employee of the electronic interaction subject who has the authority to do so. The market participant is obliged to approve by an internal document the list of market participant employees who are granted the right to use qualified electronic seals for electronic documents.

  2. The electronic interaction subject has the right to use a qualified electronic seal when providing or receiving services in electronic form or during information exchange with other electronic interaction subjects. The electronic interaction subject, whose constituent documents do not provide for the presence of a physical seal, has the right to use a qualified electronic seal to confirm the integrity and origin of information during information interaction.

  3. Verification and confirmation of a qualified electronic seal is carried out within the framework of receiving a qualified electronic trust service for the creation, verification, and confirmation of a qualified electronic signature or seal.

  4. The electronic interaction subject has the right to use more than one qualified electronic seal.

  5. The electronic interaction subject is obliged to ensure the use of an electronic time mark in cases of applying a qualified electronic seal as defined in paragraph 65 of this section, and the corresponding electronic interaction system must ensure the verification of the presence of a qualified electronic time mark. The electronic interaction subject is obliged to verify the validity of the corresponding qualified electronic seal certificate when applying a qualified electronic seal. Verification of the validity of the qualified electronic seal certificate is carried out within the framework of receiving a qualified electronic trust service for the formation, verification, and confirmation of the validity of the qualified electronic signature or seal certificate in accordance with the requirements of the Law. The electronic interaction subject is prohibited from applying a qualified electronic seal if the qualified electronic seal certificate is invalid or if it is impossible to obtain information about its status.

X. Use of an advanced electronic seal

  1. The market participant has the right to use an advanced electronic seal for internal document flow based on its internal document.

  2. The electronic interaction subject has the right to use an advanced electronic seal when providing or receiving services in electronic form or during information exchange with other electronic interaction subjects based on a contract, taking into account the requirements of paragraph 16 of Section II of this Procedure.

  3. The market participant determines the technology for using an advanced electronic seal and the means of advanced electronic signature or seal used during its interaction with a client or counterparty.

  4. An advanced electronic seal is applied if, according to the terms of the contract, it is necessary to:

  1. certify the validity of the signature on electronic documents;
  2. apply a seal to certify the correspondence of copies of documents to originals;
  3. confirm the authority of a representative of a legal entity to use an ES in the context provided by the document (signing, approval, agreement, visa, certification, familiarization).
  1. The electronic interaction subject has the right to use more than one advanced electronic seal.

Director of the Department of Information Technologies Andrii ZAIKA

Appendix to the Procedure for the Use of Electronic Signatures by Participants of Capital Markets and Professional Participants of Organized Commodity Markets (paragraph 21 of Section II)

Standards defining requirements for the creation of qualified electronic signatures and qualified electronic seals in the creation of electronic documents that, in accordance with Ukrainian legislation, are subject to archival storage

  1. DSTU ETSI TS 102 778-2:2015 "Electronic Signatures and Infrastructures (ESI). Profiles of Advanced Electronic Signatures PDF. Part 2. Basic PAdES - profiles based on ISO 32000-1 (ETSI TS 102 778- 2:2009, IDT)".
  2. DSTU ETSI TS 102 778-3:2015 "Electronic Signatures and Infrastructures (ESI). Profiles of Advanced Electronic Signatures PDF. Part 3. Enhanced PAdES - PAdES-BES and PAdES-EPES profiles (ETSI TS 102 778- 3:2010, IDT)".
  3. DSTU ETSI TS 102 778-4:2015 "Electronic Signatures and Infrastructures (ESI). Profiles of Advanced Electronic Signatures PDF. Part 4. Long-term PAdES - PAdES LTV profile (ETSI TS 102 778-4:2009, IDT)".
  4. DSTU ETSI TS 102 778-5:2015 "Electronic Signatures and Infrastructures (ESI). Profiles of Advanced Electronic Signatures PDF. Part 5. PAdES for XML content - profiles for XAdES signatures (ETSI TS 102 778- 5:2009, IDT)".
  5. DSTU ETSI EN 319 142-1:2016 (ETSI EN 319 142-1:2016, IDT) "Electronic Signatures and Infrastructures. PAdES Digital Signatures. Part 1. Structural Elements and Basic PAdES Signatures".
  6. DSTU ETSI EN 319 142-2:2016 (ETSI EN 319 142-2:2016, IDT) "Electronic Signatures and Infrastructures. PAdES Digital Signatures. Part 2. Additional PAdES Signature Profiles".
  7. DSTU ETSI EN 319 132-1:2021 (ETSI EN 319 132-1 V1.1.1 (2016-04), IDT) "Electronic Signatures and Infrastructures (ESI). XAdES Digital Signatures. Part 1. Structural Blocks and Basic XAdES Signatures".
  8. DSTU ETSI EN 319 132-2:2021 (ETSI EN 319 132-2 V1.1.1 (2016-04), IDT)

2 Continuation of the appendix "Electronic Signatures and Infrastructures (ESI). XAdES Digital Signatures. Part 2. Advanced XAdES Signatures". 9. DSTU ETSI EN 319 122-1:2021 (ETSI EN 319 122-1 V1.2.1 (2021-10), IDT) "Electronic Signatures and Infrastructures (ESI). CAdES Digital Signatures. Part 1. Structural Blocks and Basic CAdES Signatures". 10. DSTU ETSI EN 319 122-2:2021 (ETSI EN 319 122-2 V1.2.1 (2016-04), IDT) "Electronic Signatures and Infrastructures (ESI). CAdES Digital Signatures. Part 2. Advanced CAdES Signatures". 11. DSTU ETSI EN 319 162-1:2021 (ETSI EN 319 162-1 V1.1.1 (2016-04), IDT) "Electronic Signatures and Infrastructures (ESI). Containers of Related Signatures (ASiC). Part 1. Structural Blocks and Basic ASiC Containers". 12. DSTU ETSI EN 319 162-2:2021 (ETSI EN 319 162-2 V.1.1.1 (2016-04), IDT) "Electronic Signatures and Infrastructures (ESI). Containers of Related Signatures (ASiC). Part 2. Additional ASiC Containers". 13. DSTU ETSI TS 119 132-3:2022 (ETSI TS 119 132-3 V1.1.1 (2021-01), IDT) "Electronic Signatures and Infrastructures (ESI). XAdES Digital Signatures. Part 3. Introduction of Evidence Record Syntax (ERS) mechanisms into XAdES". 14. DSTU ETSI TS 119 182-1:2022 (ETSI TS 119 182-1 V1.1.1 (2021-03), IDT) "Electronic Signatures and Infrastructures (ESI). JAdES Digital Signatures. Part 1. Structural Blocks and Basic JAdES Signatures".

More like this from NSSMC

NSSMC published 5 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share