From 1 September 2026, new QES keys in Ukraine will be issued only under the national Kupyna hashing standard. For most companies the transition will pass unnoticed — but it is better to make sure of that in advance, not on the day your accounting team urgently needs to sign a batch of documents. Here is a practical checklist to help you prepare calmly and without last-minute firefighting.
What Exactly Is Changing
A quick recap of the context: the Cabinet of Ministers has approved Kupyna (DSTU 7564:2014) as the mandatory basis for creating qualified electronic signatures. Since 10 February 2026, new QES are already being formed under the new standard, and from 1 September 2026 new keys will be issued exclusively under it. For a detailed breakdown, see our news piece on the Kupyna transition.
The key things to know upfront: existing certificates remain valid until they expire, previously signed documents keep their full legal force, and during the transition period systems support both standards in parallel. In other words, this is not an emergency — it is a matter of planned preparation.
The Preparation Checklist: Five Steps
Step 1. Audit Your Certificates and Their Validity Periods
- List every QES in the company: the director, the accountant, other signatories, and the legal entity's electronic seal.
- Record the expiry date of each certificate and who is responsible for its reissue.
- Flag the keys expiring soonest: they will be the first to move to the new standard during routine reissue. There is no need to urgently reissue keys that are still valid.
Step 2. Take Inventory of Your Software and Integrations
- List every system that works with signatures: your EDM service, ERP, CRM, bank-client systems, HR and accounting software.
- Pay special attention to in-house solutions — services that sign or verify documents via API and webhooks.
- Record software versions: you will need them for your vendor enquiries.
Step 3. Send Enquiries to Trust Service Providers and Vendors
The Ministry of Digital Transformation explicitly recommends that businesses and developers check in advance whether their software supports the new standard and contact the technical support of their services. Frame three simple questions:
- Does your system support creating and verifying QES under the Kupyna standard?
- If not yet — when is the update planned, and is any action required on our side?
- Are there any specifics for our integrations (library versions, formats, configuration)?
Keep the written replies — they are both your insurance and your argument in conversations with management.
Step 4. Update Internal Policies and Inform Your Counterparties
- Refresh your security policies: rules for storing and reissuing keys, staff instructions, and the list of responsible people.
- Explain to the team that older documents remain valid and that new keys will be issued under the new standard automatically.
- Give your key counterparties a heads-up that document exchange will continue as usual: signature verification under both standards runs in parallel.
Step 5. Plan the Key Reissue
- Do not reissue everything at once: renew keys as they expire — a new certificate will automatically be issued under the Kupyna standard.
- Use the occasion to review your key carriers: it may be time to move from a file key to a more secure option — see our comparison of Diia.Signature, file keys and tokens.
- Add reissue dates to the responsible people's calendars so no signatory ends up with an expired key.
The Checklist at a Glance
| Step | What to do | Outcome |
|---|---|---|
| 1. Certificate audit | Compile a list of all QES and their expiry dates | You know whose keys expire and when |
| 2. Software inventory | Map every system that touches signatures: EDM, ERP, CRM, bank-client | A list of integrations to verify |
| 3. Vendor enquiries | Write to trust service providers and software vendors | Written confirmations of Kupyna support |
| 4. Policies and communication | Update security policies, inform the team and counterparties | Everyone knows what changes and when |
| 5. Reissue plan | Renew keys as they expire | A smooth transition with no signing downtime |
What This Looks Like for eObig Users
If you sign documents in eObig, your IT team does not need to prepare anything separately: the platform's cryptographic core is being updated to comply with the new standard, so in-browser signing will keep working as usual — no plugins, and your private key and password will, as before, never leave your device. Learn more about the protection architecture on our security page. And if you want a deeper understanding of what Kupyna changes technically, read our explainer on Ukrainian cryptography.
Key Takeaways
- Before 1 September 2026, walk through five steps: certificate audit, software inventory, vendor enquiries, policy updates, and a reissue plan.
- Existing keys remain valid until they expire — no urgent reissue is needed.
- Custom integrations deserve the most attention: ERP, CRM, bank-client systems and in-house services.
- Written confirmations from trust service providers and vendors are your best insurance.
- Previously signed documents keep their full legal force, and systems support both standards in parallel.
Work through this checklist over a few weeks — and the Kupyna transition will be nothing more than a line in the news for your company. Start for free at portal.eobig.com or book a demo: we will show you how to organise signing and document exchange so that the change of standards never bothers you.