+ 389 2 320 8090 contact@lblaw.com.mk

North Macedonia’s Cybersecurity Act: What the June 2026 Entity Lists Mean for Your Business

Since 25 June 2026, the Government of North Macedonia has published the official lists naming the sectors, entity types, and (for many) the specific companies and institutions that must comply with the Law on Network and Information System Security (the NIS Law), the country’s implementation of the EU’s NIS2 Directive. If your organization operates in energy, banking, healthcare, transport, digital infrastructure, food production, manufacturing, telecoms, or several other sectors, you may now be classified by law as an essential or important entity — with binding cybersecurity, incident-reporting, and governance duties that already apply. This guide explains who is covered, what the June 2026 lists actually changed, and what to check first. It is part of our practice in business and corporate law in North Macedonia.

What Is the NIS Law and Why the June 2026 Lists Matter

The Law on Network and Information System Security was adopted by the Assembly on 27 June 2025 and published in the Official Gazette of the Republic of North Macedonia No. 135/2025 of 4 July 2025. It transposes Directive (EU) 2022/2555, NIS2 and entered into force on the eighth day after publication, with its substantive obligations applying from 1 January 2026 (Article 62).

Article 7 (1) of the Law required the Government, on proposal of the Ministry of Digital Transformation, to adopt five detailed lists within 12 months of the Law entering into force: the high-criticality sectors and entity types, the other critical sub-sectors, the essential entities, the important entities, and certain other legal persons. That 12-month clock ran out in July 2026 — and the Government met it early, with a Decision published in Official Gazette No. 140 of 25 June 2026, containing all five annexes. This is the update this page tracks.

Sixteen Sectors, Two Tiers: Who Falls Within Scope

Article 4 of the Law sets three separate scopes. First, a closed list of public-sector bodies (the Assembly, Government, ministries, state administration bodies, courts, municipalities, and the City of Skopje). Second, medium and large private entities operating in 16 named sectors. Third, a set of entities that are covered regardless of size because of the service they provide.

High-criticality sectors (Annex 1 of the June 2026 Decision)

  • Energy — electricity, district heating/cooling, oil, gas, and hydrogen operators and undertakings
  • Transport — air, rail, water, and road (including intelligent transport system operators)
  • Banking — credit institutions
  • Financial market infrastructure — trading venues and central counterparties
  • Health — healthcare providers, medical-product researchers, and critical medicine/device manufacturers
  • Drinking water supply and distribution
  • Wastewater collection and treatment
  • Digital infrastructure — internet exchange points, DNS providers, TLD registries, cloud, data-center, and CDN providers, trust service providers, public electronic communications networks/services
  • ICT service management B2B — managed service and managed security service providers
  • Public administration — central and regional government bodies

Other critical sectors (Annex 2)

  • Postal and courier services
  • Waste management
  • Manufacture, production, and distribution of chemicals
  • Production, processing, and distribution of food
  • Manufacturing — medical devices, computers/electronics/optics, electrical equipment, machinery, motor vehicles, and other transport equipment
  • Digital providers — online marketplaces, online search engines, and social-networking platforms
  • Research organizations

 

A third group is covered regardless of size or sector: public electronic-communications operators, trust-service providers, the body that runs the .mk and мкд top-level domain registry, DNS-service providers, owners or operators of designated critical infrastructure, and any entity legally designated as such following a risk assessment (Article 4(3)).

Essential vs. Important Entities — What’s the Difference?

Article 8 splits regulated entities into two tiers, and the tier decides how strict the oversight is and how large the fines can be.

Essential entities

  • Large undertakings (by employee count, turnover, or balance sheet under the Company Law) operating in any of the 16 sectors
  • Qualified trust-service providers, the .mk/мкд registry operator, and DNS-service providers, regardless of size
  • Medium and large public electronic-communications operators
  • All public-sector institutions listed in Article 4(1)
  • Owners or operators of designated critical infrastructure
  • Any entity the Government designates as essential by law or following a risk assessment

Important entities

  • Medium-sized undertakings in the high-criticality sectors that do not otherwise qualify as essential
  • Any entity designated as important by law or following a risk assessment.

 

The distinction is not academic: essential entities face proactive supervision (the competent authority can inspect at any time), while important entities are supervised ex post, only once there is an indication of non-compliance (Articles 49–52). The fine caps also differ — see the penalties section below.

What the June 2026 Decision Actually Changed

Publishing Annexes 3 and 4 means the Government has already carried out the initial classification exercise for a large number of entities. Annex 3 lists named essential entities — telecom operators, banks, hospitals, energy companies, and more — together with their registration number, address, contact details, the service they provide, and (where recorded) their IP range. Annex 4 lists important entities in the same format. Annex 5 separately lists specific legal persons the Law always treats as regulated regardless of sector, including domestic trust-service providers, several telecom operators, and the operator of the national top-level domain registry.

If your organization appears on Annex 3 or Annex 4, the classification question is settled — the obligations in the Law already apply to you. If it does not appear but meets the essential- or important-entity criteria in Article 8, the Law does not let you wait to be added: Article 8 (5) requires you to notify the competent authority that you meet the conditions. Waiting for the next update of the list is not a compliant position.

This is specifically regulated by the Government Decree on the classification methodology (reported as Official Gazette No. 133/2026 of 18 June 2026), а risk-assessment methodology for classification (reported as Official Gazette No. 128/2026 of 12 June 2026), and a methodology for prioritizing CIRT tasks (reported as Official Gazette No. 139/2026 of 25 June 2026). 

The Four-Stage Incident-Reporting Clock

Article 33 sets one of the stricter reporting timetables in the region. Essential and important entities must notify the competent CSIRT of a significant cybersecurity incident or significant cyber threat immediately, and no later than three hours after becoming aware of it — a faster first-contact trigger than the 24-hour ‘early warning’ that NIS2 sets as its EU-wide minimum. Three further stages follow.

The four reporting stages (Article 33)

  • Stage 1 – Initial notice: within 3 hours of becoming aware — flag that a significant incident or threat has occurred.
  • Stage 2 – Early warning: within 24 hours — state whether unlawful or malicious action is suspected and whether cross-border impact is possible.
  • Stage 3 – Incident notification: within 72 hours — give the initial assessment of severity and impact, plus indicators of compromise if available.
  • Stage 4 – Final report: within 1 month of the incident notification (or of resolution, if the incident is still ongoing) — detailed description, root cause, mitigation measures applied, and cross-border impact if relevant.

Reports go to the competent CSIRT: MKD-GOV-CSIRT (within the Ministry of Digital Transformation) for the central public sector, or the National Center for Response to Computer Incidents, MKD-CIRT (within the Agency for Electronic Communications), for the 16 private-sector areas and the entities under Article 4(3). Several sectors also have their own sector regulator layered on top — for example, the Energy Regulatory Commission adopted its own cybersecurity rules for the energy sector in May 2026, which largely mirror this four-stage timetable but route reports through the regulator as well as MKD-CIRT.

Cybersecurity Officers and Governance Duties

Essential entities must appoint at least one cybersecurity officer with a background in ICT, telecommunications, security, or law (Article 25).

This is in more detailes prescribed with The Rulebook on the Detailed Criteria Regarding the Size and Scope of Operations for the Establishment of an Organizational Unit, or the Designation of a Cybersecurity Officer, as well as the Detailed Criteria Regarding the Type and Number of Network and Information Systems and the Number of Employees as Conditions for Determining the Number of Cybersecurity Officers (Official Gazette No. 128/2026 of 12 June 2026) requiring public-sector institutions to appoint between one and five cybersecurity officers depending on institutional size, system complexity and data volume.

The officer acts independently of management on cybersecurity matters and reports directly to entity leadership.

Beyond the officer appointment, the management body of every essential and important entity must approve a risk assessment at least once a year and keep it current (Article 31), and must adopt risk-management measures covering, at minimum: risk and security analysis; incident handling; business-continuity and backup management; supply-chain security, including the security practices of direct suppliers; secure procurement, development, and maintenance of systems; policies for assessing the effectiveness of security measures; basic cyber-hygiene practices and staff training; cryptography and encryption policy; human-resources security and access control; and multi-factor or continuous authentication for remote access and privileged accounts (Article 32).

Penalties for Non-Compliance

The Law sets turnover-based fines that mirror the NIS2 caps: up to 2% of annual turnover for essential entities and up to 1.4% of annual turnover for important entities (Articles 54–55), alongside fixed fines of up to €5,000 in denar equivalent for the responsible individual or the head of a public-sector body. Where an essential entity ignores a corrective order, the Law also allows a temporary ban on carrying out the relevant activity, and a ban on the responsible individual holding a profession, activity, or position.

A Practical Example: Is Your Company Covered?

Working through the classification test

  • Step 1 – Sector check: A mid-size managed IT-services provider based in Skopje falls under ICT service management B2B sector, one of the ten high-criticality sectors in Annex 1.
  • Step 2 – Size check: If it qualifies as a medium-sized undertaking under the Company Law, it is presumptively an important entity under Article 8(2); if large, it is essential under Article 8(1).
  • Step 3 – Named-list check: The company searches Annex 3 (essential) and Annex 4 (important) of the June 2026 Decision by name and registration number.
  • Step 4 – If listed: the classification is confirmed — the company proceeds directly to risk assessment, officer appointment, and incident-reporting readiness.
  • Step 5 – If not listed but the criteria are met: Article 8(5) requires the company to notify the competent authority (MKD-CIRT, via the Agency for Electronic Communications) that it meets the conditions — rather than waiting to be added to a future list.

North Macedonia’s Cybersecurity Regime in 2026 — What to Check Now

The legal framework is now largely in place: the Law, the classification and risk-assessment methodologies, and the named entity registers. What is still missing, as of this update, is the implementing act on the detailed risk-management measures themselves (referenced in Article 32 but not yet published as a standalone act at the time of writing). Businesses in the 16 covered sectors should check the following now.

  • Search Annex 3 and Annex 4 of the June 2026 Decision (Official Gazette No. 140/2026) for your company by name and registration number.
  • If you are not listed but operate in a covered sector as a medium or large undertaking, assess whether you meet the essential- or important-entity criteria in Article 8 and, if so, notify the competent authority without waiting to be added to the register.
  • Confirm whether your company has appointed a cybersecurity officer who meets the Article 25 qualification requirements.
  • Check that your incident-response procedure can meet the 3-hour / 24-hour / 72-hour / 1-month reporting clock in Article 33, and that you know which CSIRT to notify.
  • If you supply ICT products or services to a regulated entity, expect new contractual security requirements to flow down to you under the Article 32(4) supply-chain rules — even if you are not directly regulated yourself.

Frequently Asked Questions

Is my company automatically covered because it appears in the June 2026 registry?

Yes — if your company is named in Annex 3 or Annex 4 of the Government’s Decision (Official Gazette No. 140/2026), the Government has already classified it as essential or important respectively, and the Law’s obligations apply from that classification. Being listed does not create the obligation; it confirms it — the obligation flows from meeting the criteria in Article 8 of the Law.

What if my company isn’t on the government’s list but I think we qualify?

You still have to comply, and you have to say so. Article 8 (5) of the Law requires an entity that meets the essential, or important-entity criteria but is not on the published lists to notify the competent authority itself. The Government updates the lists periodically, but the notification duty is not conditional on waiting for that update.

How fast must we report a cybersecurity incident?

For a significant incident or significant cyber threat, notify the competent CSIRT immediately, and no later than three hours after you become aware of it. Formal early-warning, detailed, and final reports follow at 24 hours, 72 hours, and one month respectively, under Article 33.

What’s the penalty for non-compliance?

Fines can reach 2% of annual turnover for essential entities and 1.4% for important entities, plus fixed fines for the responsible individual and, for essential entities that ignore a corrective order, a possible temporary ban on the relevant business activity (Articles 54–56).

Does the NIS Law apply to companies without a registered seat in North Macedonia?

It can. Foreign providers of DNS services, cloud computing, data-centre services, CDN services, managed (security) services, domain-name registration services, online marketplaces, search engines, or social-networking platforms, and providers to essential or important entities, must register a local representative with the Ministry of Digital Transformation under Article 9. Public-sector bodies are barred from awarding public contracts to such providers if they have not done so.

 

Every classification question turns on your organization’s specific size, sector, and services — and the consequences of getting it wrong (or leaving it unassessed) now include the notification duty and the fines above. If you want us to review where your company sits under the June 2026 lists and what your obligations are, the team at Lalicic & Partners can walk through it with you in a consultation.

Note: The above does not constitute legal advice and in no way can be accepted or understood as an instruction to act in a specific case. Each legal situation has its own characteristics that should be reviewed at separately, and for that reason we recommend that you contact a professional – a lawyer – for legal advice.