World Watch/Montenegro/Cybersecurity

Cybersecurity · Montenegro

Cybersecurity regulation in Montenegro (2026)

Comprehensive lawLaw on Information Security (Zakon o informacionoj bezbjednosti), Official Gazette No. 113/2024, in force December 5, 2024; aligned with EU NIS2 Directive (2022/2555); supervised by the newly established Cybersecurity Agency and CIRT.MECountry index 79 · B+

Montenegro shaded by its cybersecurity status

Montenegro enacted a comprehensive Law on Information Security in November 2024 (in force December 2024), explicitly transposing the EU NIS2 Directive as part of its Chapter 10 EU accession negotiations. The law covers both public and private entities across essential sectors, introduces mandatory incident reporting timelines, and establishes a new Cybersecurity Agency as the central competent authority alongside the existing CIRT.ME for state bodies. A complementary National Cybersecurity Strategy 2022–2026 provides the strategic roadmap.

Key points

Comprehensive NIS2-aligned law (2024)

The Law on Information Security was adopted by the Parliament on 19 November 2024 and published in Official Gazette No. 113/2024, entering into force on 5 December 2024. It is explicitly modelled on EU Directive 2022/2555 (NIS2) and was required for Montenegro's Chapter 10 EU accession talks.

Scope: key and important entities

The law applies to state authorities, local self-government units, and private legal entities classified as 'key' or 'important' across sectors including energy, transport, banking, health, water, digital infrastructure, and public administration — mirroring NIS2's annex-based sectoral coverage.

Incident reporting obligations

Entities must report incidents that could significantly affect service continuity to the Cybersecurity Agency (or CIRT.ME for state bodies) within 24 hours as an early warning. Incidents are classified as low, medium, or high impact with escalating response duties; a major cyber crisis can trigger a government-declared national cyber crisis.

Cybersecurity Agency — new competent authority

The Government of Montenegro formally established a National Cybersecurity Agency in 2024 as the umbrella supervisory and coordination body. The existing CIRT.ME (handling state-body incidents) is to be absorbed into the Agency, though full operationalization was still in progress as of late 2024.

National Cybersecurity Strategy 2022–2026

The government adopted the Cybersecurity Strategy 2022–2026 with one strategic goal: building a sustainable system capable of detecting and defending against complex cyber threats. It mandates intersectoral coordination, military cyber capability development, and reorganization of CIRT.ME under the new Agency.

EU accession driver and Council of Europe membership

Transposing NIS2 is a binding requirement under Montenegro's EU accession Chapter 10 (Information Society and Media). Montenegro is also a party to the Council of Europe Budapest Convention on Cybercrime and participates in the CoE Octopus community for cybercrime cooperation.

Montenegro - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →