Select your language

UALinux Secured*Pack and Common Criteria

In October 2025, the State Service of Special Communications and Information Protection completed the process of Ukraine’s accession to the Common Criteria Recognition Arrangement (CCRA).

Thus, in information and communications systems designed to process government information, or other types for which requirements are established by the state, the use of both Common Criteria-certified encryption algorithms and modules (which must comply with FIPS 140-3 with confirmation) and those with a cryptographic conclusion from the State Special Communications Service is permitted.
FIPS 140-3 is a US and Canadian government standard defining security requirements for cryptographic modules (hardware and software systems that encrypt data).

UALinux Secured*Pack 20.04/22.04/24.04 fully complies with new security requirements. The operating system includes FIPS 140-3 cryptographic modules (certified by NIST as part of Ubuntu 20.04/22.04/24.04) in a closed repository and supports their use, as well as modules certified by the State Service of Special Communications and Information Protection.
FIPS 140 support is not yet available in Ubuntu 26.04.

Also, using FIPS 140-3 cryptographic modules, disk encryption can be performed, which will meet the new requirements of the regulatory documents of the Technical Information Security system in the section on authorization, in particular, the requirements for protecting information at rest.

BUT.
In connection with the implementation of global standards for assessing security measures and the state of cybersecurity in information and communication systems, a situation has arisen in which the requirements for the use of cryptographic tools are interpreted in an ambiguous manner.

There is still no clear distinction as to what information can be processed using certified cryptographic modules that have international certifications harmonized in Ukraine (such as FIPS 140-3), since the current assessment of technical/cryptographic information protection tools (in particular, the confirmation of KV, CV, NV services) does not recognize anything other than national cryptographic algorithms and solutions that have a conclusion from the State Service of Special Communications and Information Protection in the field of cryptographic information protection.