World Watch/North Macedonia/Cybersecurity

Cybersecurity · North Macedonia

Cybersecurity regulation in North Macedonia (2026)

Comprehensive lawLaw on Security of Network and Information Systems (Official Gazette No. 135, 04.07.2025), in force 1 January 2026; aligned with EU NIS2 Directive (2022/2555). Administered by the Ministry of Digital Transformation and MKD-CIRT (National Centre for Computer Incident Response) under the Agency for Electronic Communications.Country index 77 · B+

North Macedonia shaded by its cybersecurity status

North Macedonia enacted a comprehensive, NIS2-aligned cybersecurity law in July 2025, which became applicable on 1 January 2026, replacing a fragmented set of partial rules with a unified legal framework. The law classifies regulated entities as essential or important, mandates tiered incident notification, and establishes supervisory and enforcement powers. This is complemented by the National Cybersecurity Strategy 2025–2028, adopted by government in January 2025.

Key points

Comprehensive NIS2-aligned law

The Security of Network and Information Systems Act (Official Gazette No. 135, 04.07.2025) harmonises North Macedonia's national legislation with EU Directive 2022/2555 (NIS2), introducing for the first time a single, unified cybersecurity framework covering essential and important entities across critical sectors.

Entity classification and obligations

Entities are classified as essential or important. Both categories are subject to defined cybersecurity risk-management measures and reporting obligations under Chapter IV of the Act; essential entities face stricter supervisory scrutiny.

Tiered incident-notification duties

Regulated entities must issue an early warning within 24 hours, submit an initial assessment within 72 hours, and provide a final report within one month of a significant incident. Additionally, entities must notify the competent incident-response team (MKD-CIRT) within three hours of becoming aware of an incident or cyber threat.

Sanctions regime

Essential entities may be fined up to 2% of total annual worldwide revenue for the preceding year; important entities face fines up to 1.4% of annual revenue. MKD-CIRT holds supervisory power to impose measures on non-compliant entities.

National Cybersecurity Strategy 2025–2028

Adopted by the government in January 2025, the strategy sets five priority areas including establishing a dedicated cybersecurity sector within the Ministry of Digital Transformation, expanding MKD-CIRT capabilities, and aligning with EU frameworks (NIS2, Cybersecurity Act) and ITU/ENISA guidance.

MKD-CIRT as national CSIRT

MKD-CIRT, operating under the Agency for Electronic Communications, is the designated national computer incident response team serving as the official national point of contact and coordination for cybersecurity incidents; under the new Act it also exercises supervisory authority over regulated entities.

North Macedonia - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →