The official text of the relevant order issued by the Operational-Analytical Centre under the President of the Republic of Belarus has already been published on the pages of the National Legal Internet Portal. It has been established that these adjustments will start to be applied in practice from July 1, 2026. It is worth noting that these innovations represent not a radical change of course, but a consistent and logical stage in the development of the system. According to clarifications from representatives of the National Centre for Cyber Security, the preparation of the updates was based on a detailed analysis of law enforcement practice in this area, as well as on the experience accumulated during the operation of cyber security centres. Furthermore, during the development of the changes, numerous initiatives and proposals received from government bodies and other organisations participating in the national security system were comprehensively considered and taken into account.
Why does cybersecurity concern every legal entity?
In accordance with the provisions of Decree No. 40 "On Cybersecurity", the national system for ensuring cybersecurity includes not only specialised units but also the information infrastructure of all organisations operating within the country. This implies that since 2023, cybersecurity requirements, to varying degrees, are applicable to every legal entity in Belarus. It should be noted that these specialised rules do not apply to individuals, including individual entrepreneurs.
For clarity, a parallel can be drawn with traffic regulations. There are stricter standards for vehicle drivers, who are only permitted to participate in traffic if they possess a relevant license. However, the traffic rules themselves are mandatory for all participants to observe – from motorists to pedestrians. The widespread adoption of modern digital technologies in all aspects of human activity dictates the need for universal vigilance: even if an information infrastructure asset of a specific organization does not, in itself, present an obvious interest to cybercriminals due to the importance of the automated business processes or the volume of information processed, this does not mean it is outside the zone of potential risk. Modern cyberattack strategies are often built on the principle of a "chain of compromise," where attackers actively seek the most vulnerable link in the overall digital ecosystem.
Once control is established over such a seemingly "uninteresting" asset, a cybercriminal can use it to organize distributed denial-of-service (DDoS) attacks targeting government portals, the banking system, or critical information facilities. Compromised resources can also be used for the mass distribution of malicious software and phishing campaigns within the country, as well as for creating covert command centers designed to control botnets and for other malicious activities. Consequently, even the compromise of a relatively ordinary asset turns it into a tool for carrying out attacks on facilities related to national information infrastructure, such as banks, energy grids, transport hubs, and public administration systems. It is precisely for this reason that ensuring a basic level of cybersecurity for all organizations whose information systems have access to the Internet is not anyone's arbitrary whim, but a fundamental element of the collective defence capability of the entire national cyberspace.
New Requirements as a Response to Market Realities
When developing the current amendments, the key principle was to ensure the practical feasibility of cybersecurity legislation for all participants in the national system – from large specialized cybersecurity centres to small organisations with Internet access. Excessive or clearly unfeasible requirements do not contribute to improving the level of protection; on the contrary, they can provoke a formal approach to their implementation and create only an illusion of security. The new version of Order No. 130 carefully balances the interests of the state, which strives for the stability of the national information infrastructure; organisations expecting predictability and reasonable costs; and conscientious participants in the cybersecurity services market, who receive clear and transparent rules of the game.
An important addition to the above is the fact that a significant part of the introduced changes is aimed not at forming completely new rules to which market participants will have to adapt anew, but rather at legally consolidating already established social relations in the area under consideration. The regulator, analysing law enforcement practice over three years, brings the regulatory framework into line with the de facto established behavioural patterns and expectations of all involved parties.
Legislative Updates. What Has Changed?
There has been a significant improvement in the terminological base. To ensure uniform application of legal norms, Order of the OAC No. 130 has been supplemented with an exhaustive list of terms and their corresponding definitions. The development of a unified terminological apparatus contributes to the elimination of any ambiguities in interpretation and lays a solid foundation for subsequent norm-setting and law enforcement activities.
The adjustments made to the cyber incident level system (now three instead of the previously existing two) aim to further move the field of cybersecurity out of a purely technical paradigm.
Cybersecurity is not an isolated phenomenon; it is intrinsically linked to the processes it is designed to protect in key areas such as public administration, industry, social services, and many others. It represents a critically important component influencing all aspects of national security, from economic and environmental stability to political and social resilience. This extends beyond the narrow technical task of engineers and specialists. It is a comprehensive, systemic activity focused on ensuring the continuity and sustainability of vital processes.
The new approach adopted is based on the principle of determining the criticality level of an incident, considering the potential scale of its negative consequences. A cyber incident, identical in its technical nature but occurring in a small organisation without significant negative repercussions, cannot be classified at the same level as a similar incident affecting the owner of critical information infrastructure. Examples of high-level incidents now include events capable of disrupting the operation of critical information facilities for a period exceeding three hours; compromising the confidentiality of biometric, genetic, or personal data of over 100,000 individuals; and disseminating false socially significant information.
This change possesses not only conceptual but also significant practical legal importance. From 19 June 2026, Articles 23.11 and 23.12 of the Code of Administrative Offences (KoAP) will come into force, establishing liability in the field of cybersecurity assurance. This administrative liability applies exclusively under the condition of a cyber incident classified as high-level. Consequently, the updated classification forms the necessary legal foundation for the proportionate and differentiated application of state enforcement measures adequate to the degree of public danger of the committed act.
Optimising Interaction with the Regulator: From Formalism to Applied Effectiveness
A significant change is the removal of the obligation for cybersecurity centres to regularly submit cybersecurity assurance regulations and incident response action plans to the OAC. These documents are now considered for internal use only.
Their key role is not to fulfil reporting functions to a state body, but to ensure high-quality operational activities. The regulations set standards for interaction with information infrastructure assets, and the response plan provides a clear action algorithm in the event of threats. It is these documents that serve as the foundation for the transparency and predictability of processes for the centres themselves and their clients within the framework of contractual obligations.
This measure is aimed at eliminating administrative barriers and reducing excessive paperwork. Given the need for constant updating of these materials, their mandatory submission to the OAC had lost its practical meaning. However, the regulator retains the right to request the specified documentation in the event of cyber incidents or during inspection activities.
To maintain oversight of the overall state of cybersecurity in the country, a simplified reporting mechanism is being introduced. Cybersecurity centres will provide summarised data on their work, audit results, and security assessments twice a year: for the first half of the year (by July 5) and for the calendar year (by January 5).
This format allows the OAC to effectively monitor industry dynamics and identify systemic risks without excessive interference in the companies' operational activities. As a result, an optimal balance is achieved: cybersecurity centres are relieved of burdensome reporting while maintaining internal planning discipline and transparency for the regulator within the principle of "reasonable sufficiency".
Development of Human Resources and Standardisation of Cybersecurity Services
Editorial changes to the typical structure of cybersecurity centres have been made to enhance clarity and accessibility for law enforcement practitioners, while the total number of designated roles remains the same.
However, for CСB providing services to third-party organisations, a mandatory requirement for in-house specialists in malware analysis and security assessment effectiveness is introduced. This innovation is designed to significantly strengthen key competencies within the national cybersecurity system. The concentration of experts in reverse engineering and cyberattack modelling within organisations' staff will contribute to the enhancement of overall potential, which is critically important in the face of increasing complexity of cyber threats. The engagement of external resources (outsourcing) to perform these functions is permitted, but exclusively as a supplementary measure, not a complete replacement for in-house specialists.
The new version of Order No. 130 provides for the adjustment of essential terms of contracts concluded for the provision of cybersecurity services. The aim of these changes is to establish clear and transparent rules for the functioning of this market segment.
Over the past three years, the state has closely monitored the expectations of customers and the offerings of CCBs. The regulation of essential terms is due to the fact that it is the state that determines a significant portion of organisations for which the acquisition of such services (or the creation of their own centres) is mandatory. In developing this approach, on 14 May 2026, Resolution of the Council of Ministers No. 246 was adopted. In this situation, the state assumes responsibility for ensuring that mandatory procurements are carried out in accordance with clear and unified rules, excluding unfair performance of contractual obligations.
Unification of Approaches to Audit and Security Assessment
The most significant substantive amendments have been made to the regulations for conducting cybersecurity audits and assessing the effectiveness of information system protection.
Previously, the lack of legislative detail in these procedures created uncertainty for customers: lacking specialised competencies, they effectively purchased services without a guarantee of quality. This stimulated the emergence of unscrupulous providers in the market who used dumping and substituted thorough analysis with formal automated scanning.
Новая редакция приказа ОАЦ №130 вводит строгий регламент данных процессов. Это обеспечивает стратегические преимущества для всех участников системы. Организации-заказчики получают прозрачные критерии оценки объема, содержания и качества выполняемых работ. Добросовестные центры кибербезопасности получают равные рыночные условия, исключающие конкуренцию с компаниями, не способными обеспечить выполнение установленных стандартов.
Оптимизация порядка информационного взаимодействия
Положение о порядке взаимодействия элементов национальной системы кибербезопасности изложено в новой редакции, устанавливающей четкую структуру каналов связи. В частности, взаимодействие Национального центра кибербезопасности с госорганами и иными организациями теперь официально допускает использование телефонной связи и электронной почты.
Данный подход продиктован необходимостью оперативного реагирования, так как минимизация последствий кибератак напрямую зависит от скорости начала защитных мероприятий. Выбор именно этих каналов связи обусловлен рядом факторов.
Доступность в кризисных ситуациях. При компрометации систем или выходе из строя сетевых сегментов специализированные защищенные каналы могут быть недоступны, тогда как телефонная связь и электронная почта остаются наиболее отказоустойчивыми средствами коммуникации.
Сохранение доказательной базы. Своевременный контакт с Национальным центром позволяет оперативно зафиксировать индикаторы компрометации, локализовать угрозу и предотвратить её распространение на смежные инфраструктурные объекты. Ожидание восстановления штатных каналов связи чревато потерей критически важных улик.
Гибкость системы. Предусмотрена возможность использования любых иных способов взаимодействия, не запрещенных законодательством, что позволяет адаптироваться к любым нештатным сценариям.
Кроме того, новая редакция закрепляет необходимость согласования с ОАЦ передачи информации о киберинцидентах международным или иностранным организациям. Ранее эта функция была монополизирована ОАЦ как «единым окном». Современный подход сохраняет за государством контроль над трансграничной передачей данных, обеспечивая при этом необходимый баланс между государственным суверенитетом и оперативностью реагирования на трансграничные угрозы.
Модернизация регламента работы команд реагирования на киберинциденты
The updated Regulation on the procedure for the activities of national response teams and similar structures in cybersecurity centres is aimed at improving the efficiency and standardisation of actions in neutralising cyber threats.
Key innovations include the following.
Digital transparency of processes. The progress of all response activities is now mandatorily recorded in the cyber incident information processing system. This ensures strict documentation of actions and creates a basis for a qualitative analysis of the effectiveness of measures taken in the future.
Harmonisation of evidence preservation recommendations. A norm is being introduced whereby all actions to ensure the preservation of information necessary for detecting indicators of compromise must be carried out in strict accordance with the recommendations of the OAC. This material will be published on the official website of the agency (oac.gov.by) by 1 July 2026. Notably, these protocols can be used not only by professional response teams but also by any organisation.
The preservation of digital footprints is a crucial stage in combating the consequences of cyberattacks. Unprofessional actions by personnel leading to the destruction or alteration of data make a quality investigation impossible. Adherence to established recommendations helps prevent the irreversible loss of evidence, which is critically important for identifying attack vectors, deanonymizing attackers, and subsequently protecting infrastructure from similar incidents.
Update of Cybersecurity Requirements for Information Infrastructure Facilities
Appendix 4, containing cybersecurity requirements for information infrastructure facilities, has been revised to enhance its practicality and adaptation to real operating conditions. This section is one of the key elements of the document, as its provisions apply to all organizations in the Republic of Belarus.
The new version of the requirements is characterised by clearer wording and provides, in particular, for the possibility of engaging third-party Belarusian organisations or individual entrepreneurs to perform relevant work in the absence of own resources. It is important to note that this activity is not subject to licensing. Overall, the amendments introduced provide organisations with flexibility in building cybersecurity systems, taking into account their specific needs and available resources, while guaranteeing the maintenance of the mandatory minimum level of security.
Thus, the adopted amendments are a logical stage in the evolution of the national cybersecurity system, taking into account the experience gained since the entry into force of Decree No. 40 in 2023. The regulator is consistently moving from the formation of the system's basic architecture to its substantive content. This involves the legitimisation of established social relations, the reduction of excessive administrative burden, the introduction of clear professional standards, the development of the terminological base, and the improvement of interaction mechanisms. Particular attention is paid to the transition from an exclusively technical approach to cybersecurity to a risk-oriented one, taking into account the scale of potential consequences of cyber incidents for all areas of national security.
Organisations that have or plan to establish cybersecurity centres are recommended to conduct a thorough analysis of their activities' compliance with the new requirements. Special attention should be paid to staffing (the availability of in-house analysts for detecting malicious software and penetration testers for centres providing services) and readiness to undergo annual audits and security assessments in accordance with a unified methodology.
All other organisations are advised to review their approaches to basic cybersecurity aspects. It is necessary to consider that even a seemingly insignificant object can become a vulnerable link in the national system. The relevance of this is underscored by the tightening of administrative liability legislation for violations in this area.
Based on materials from BELTA. Photos from open sources.