World Watch/Montenegro/Cybersecurity

Cybersecurity · Montenegro

Cybersecurity - Montenegro

Comprehensive lawLaw on Information Security (Zakon o informacionoj bezbjednosti), Official Gazette No. 113/2024, in force December 5, 2024; aligned with EU NIS2 Directive (2022/2555); supervised by the newly established Cybersecurity Agency and CIRT.ME

Montenegro enacted a comprehensive Law on Information Security in November 2024 (in force December 2024), explicitly transposing the EU NIS2 Directive as part of its Chapter 10 EU accession negotiations. The law covers both public and private entities across essential sectors, introduces mandatory incident reporting timelines, and establishes a new Cybersecurity Agency as the central competent authority alongside the existing CIRT.ME for state bodies. A complementary National Cybersecurity Strategy 2022–2026 provides the strategic roadmap.

Comprehensive NIS2-aligned law (2024)

The Law on Information Security was adopted by the Parliament on 19 November 2024 and published in Official Gazette No. 113/2024, entering into force on 5 December 2024. It is explicitly modelled on EU Directive 2022/2555 (NIS2) and was required for Montenegro's Chapter 10 EU accession talks.

Scope: key and important entities

The law applies to state authorities, local self-government units, and private legal entities classified as 'key' or 'important' across sectors including energy, transport, banking, health, water, digital infrastructure, and public administration — mirroring NIS2's annex-based sectoral coverage.

Incident reporting obligations

Entities must report incidents that could significantly affect service continuity to the Cybersecurity Agency (or CIRT.ME for state bodies) within 24 hours as an early warning. Incidents are classified as low, medium, or high impact with escalating response duties; a major cyber crisis can trigger a government-declared national cyber crisis.

Cybersecurity Agency — new competent authority

The Government of Montenegro formally established a National Cybersecurity Agency in 2024 as the umbrella supervisory and coordination body. The existing CIRT.ME (handling state-body incidents) is to be absorbed into the Agency, though full operationalization was still in progress as of late 2024.

National Cybersecurity Strategy 2022–2026

The government adopted the Cybersecurity Strategy 2022–2026 with one strategic goal: building a sustainable system capable of detecting and defending against complex cyber threats. It mandates intersectoral coordination, military cyber capability development, and reorganization of CIRT.ME under the new Agency.

EU accession driver and Council of Europe membership

Transposing NIS2 is a binding requirement under Montenegro's EU accession Chapter 10 (Information Society and Media). Montenegro is also a party to the Council of Europe Budapest Convention on Cybercrime and participates in the CoE Octopus community for cybercrime cooperation.

Machine-assisted translation · verified 5/24/2026 · orientation, not legal advice. English version →