World Watch/Serbia/Cybersecurity

Cybersecurity · Serbia

Cybersecurity regulation in Serbia (2026)

Comprehensive lawLaw on Information Security (Zakon o informacionoj bezbednosti), Official Gazette RS No. 91/2025, adopted 22 October 2025, in force 31 October 2025; NIS2-aligned successor to the 2016 Information Security Law; supervised by RATEL/National CERT (current) and the forthcoming Office for Information Security (operational 1 January 2027)Country index 81 · B+

Serbia shaded by its cybersecurity status

Serbia enacted a comprehensive, NIS2-aligned Law on Information Security in October 2025, replacing the 2016 framework and broadening the scope of regulated ICT system operators into 'essential' and 'important' categories across sectors including healthcare, transport, energy, IT services, food, and postal services. The law introduces formal governance obligations, structured incident classification, mandatory incident reporting within 24 hours, and a 18-month compliance window for operators. A new Office for Information Security, which will consolidate National CERT and Government CERT functions, is mandated to begin operations on 1 January 2027.

Key points

NIS2 Transposition

The 2025 law explicitly harmonises Serbian law with EU NIS2 Directive (2022/2555). Serbia, as an EU accession candidate, is obliged to align its acquis; the law mirrors NIS2's dual-tier (essential/important operators) classification and sector coverage.

Incident Reporting Obligations

Operators of ICT systems of special importance must notify the national CERT without delay and at the latest within 24 hours of becoming aware of a significant incident. Operators must also submit annual statistical reports and notify near-miss threats. Fines for non-reporting reach RSD 2,000,000 (~EUR 16,800) for legal entities.

Governance & Risk Management Requirements

Operators must adopt a Risk Assessment Policy (based on methodology issued by national CERT) and an Information Security Policy. Technical requirements align with ISO 27001:2022 principles, covering secure configuration, access controls, monitoring, and business continuity.

Institutional Framework Transition

RATEL currently houses the National CERT (SRB-CERT) and oversees compliance. The new law creates the Office for Information Security, which will act as National CERT, Government CERT, single point of contact for international cooperation, and manager of the national vulnerability database; it commences operations 1 January 2027.

Compliance Timeline

ICT system operators have 18 months from the law's entry into force (i.e., approximately to April/May 2027) to bring their systems and documentation into compliance with the new requirements. The 2016 law remains partially applicable during the transition period.

Data Breach Notification (Personal Data)

Parallel to the cybersecurity law, Serbia's Personal Data Protection Act requires controllers to notify the Commissioner within 72 hours of a personal data breach posing risk to individuals' rights, and to notify affected data subjects without undue delay where the risk is high.

Serbia - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →