Montenegro replaced its 2010 information security statute with a new Law on Information Security (Zakon o informacionoj bezbjednosti), published in the Official Gazette of Montenegro no. 113/2024 on 27 November 2024 and in force from the eighth day after publication. It aligns Montenegrin law with the EU's NIS2 Directive (Directive (EU) 2022/2555), created a Cyber Security Agency (Agencija za sajber bezbjednost) to supervise it, and — this is the part most foreign companies miss — it does not stop at banks, utilities and telecoms.
The Act applies to companies, other legal persons and natural persons that access or handle data and use and manage a network and information system (Article 2). If your Montenegrin company runs its own servers, cloud accounts, a booking platform or an office network, you are inside it. What changes with the tier you fall into is how much you must do, whether you need an ISO/IEC 27001 certificate, and which fine applies.
Sources, checked 11 September 2026: the Act as published in "Sl. list CG" 113/2024, read from the Official Gazette's own page images (Articles 1–81); the gazette record lists no amending act. General information about Montenegrin law, not advice on a particular system or incident.
Three tiers, and the bottom one is almost everyone
| Tier | Who | What the Act requires | Fine for the company |
|---|---|---|---|
| Key entity (ključni subjekt) | Designated by the Government in the listed sectors (Articles 4(1), 19(1)) | All security measures in Articles 11 to 16; ISO/IEC 27001 certificate and periodic re-checks (Article 18(1), (4)-(6)) | €500 to €20,000 (Article 68) |
| Important entity (važni subjekt) | Designated by the Government in the listed sectors (Articles 4(2), 19(2)) | All security measures in Articles 11 to 16 (Article 18(1)) | €500 to €10,000 (Article 69) |
| Every other company using a network and information system | Any "other entity" under Article 2 | Security measures in Articles 11 to 15; a designated employee; incident assessment and reporting (Articles 18(2)-(3), 28-34) | €500 to €5,000 (Article 70) |
The responsible person within the company faces €30 to €1,500 in each tier (Articles 68(2), 69(2), 70(2)), and repeating a breach listed in Article 70 can lead to a ban on carrying on the profession, activity or duty for three to six months (Article 70(3)).
Size does not take you out
Montenegro's Act does not use company size to decide who is in scope. It defines key and important entities by what they do and what would happen if they stopped — and says expressly that designation applies regardless of size within the meaning of the accounting legislation (Article 4(1) and (2)). A small company that runs something the state depends on can be designated. And the bottom tier has no size filter at all: Article 18(2) obliges bodies and other entities that are not designated to apply the measures in Articles 11 to 15, and Article 18(3) obliges all of them to appoint an employee to monitor those measures.
The sectors
| Key entities — sectors (Article 19(1)) | Important entities — sectors (Article 19(2)) |
|---|---|
| Energy: electricity, district heating and cooling, oil, gas, hydrogen | Postal and courier services |
| Transport: air, rail, maritime, road | Waste management |
| Banking (credit institutions) | Manufacture and distribution of chemicals |
| Financial market infrastructure | Food production, processing and distribution |
| Health: primary, secondary and tertiary care, reference laboratories, medicines research | Manufacturing: medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment |
| Drinking water | Digital providers: online marketplaces |
| Waste water | Research organisations |
| Digital infrastructure: internet exchange points, DNS, top-level domain registries, cloud computing, data centres, content delivery networks, qualified trust service providers, public electronic communications | |
| ICT service management | |
| Public administration | |
| Space |
Entities in the key-entity sectors that are not designated as key can still be designated as important if they meet the Article 4(2) criteria (Article 19(3)).
How you find out — and why a buyer cannot simply check
Designation runs through the ministries, not through an application you file.
- The ministry responsible for the sector compiles a list of bodies and entities and asks them for data — name, seat, tax number, responsible person, official electronic address, contact phone, activity and sector (Article 20(1)-(2)). You must reply within seven days of the request and report changes within 14 days (Article 20(3)-(4)).
- Sectoral proposals go to the Ministry, which prepares a consolidated proposal; the Government adopts the List of key and important entities (Articles 21-22). The Act gave the ministries nine months from entry into force to submit their sectoral proposals (Article 72).
- The sector ministry must notify each designated entity within seven days of the List being adopted (Article 23), and designated entities must report changes to their registered data immediately (Article 26(1)).
- The List, the sectoral and consolidated registers and the underlying data are classified (Article 27).
That last point matters in a transaction. You cannot confirm from a public register whether a Montenegrin target company is a key or important entity. The only reliable source is the target itself: ask for any Article 20 data request, any Article 23 notification, and the state of its Article 18 compliance and certification. The rest of the diligence sequence is in buying a Montenegrin company: the share deal.
What the security measures are
The Act frames two families of measures (Article 11): protection of data — rules for handling data, records of access and oversight of data security (Article 12) — and protection from cyber threats and incidents — physical protection, protection of the network and information system across its whole life cycle, and cyber-risk management (Articles 13-16).
Cyber-risk management is the part reserved to key and important entities (Article 16): a risk and security analysis; incident-handling rules for prevention, detection and response; a business continuity and crisis plan; an act governing supply-chain security with suppliers and service providers; acts on establishing and maintaining systems; cryptographic protection where the work requires it; and rules for assessing whether all of that works. The detailed content of the measures is set by Government decree (Article 17). The Act gave six months for the new implementing acts and kept the old ones in force until then (Article 71) — check which instrument governs your file on the day you act.
The incident clock
Every body and entity covered by the Act, not only designated ones, must assess the impact of a cyber threat or incident on the continuity of its services, using four criteria: users who could not access the service, users with significant difficulty, duration, and geographic spread (Article 28).
| Situation | What must be sent, and when | Article |
|---|---|---|
| No impact on service continuity | A report on those threats and incidents to the Agency once a month, and you handle them yourself | 29 |
| Could significantly affect continuity | Initial notification within 24 hours of learning of it, on the prescribed form | 30 |
| Level set | The Agency (or, for state administration, its CIRT) classifies the incident as low, medium or high | 31 |
| Medium-level incident | First report within 72 hours of the initial notification; a special report without delay on new facts; continuing reports every 72 hours; final report within 30 days of resolution | 33 |
| High-level incident | First report within 72 hours; special report without delay; continuing reports every 24 hours; final report within 30 days of resolution | 34 |
| Not resolved within 10 days of the initial notification | The Ministry may propose that the Government declare a cyber crisis | 35 |
Every one of those notifications, reports and guidance notes is classified (Article 37). And each missed step — the monthly report, the 24-hour notice, each 72-hour or 24-hour report, the final report — is a separately listed misdemeanour for any legal person (Article 70(1), items 5 to 15).
Where an incident involves personal data, the Act sends you to the data protection statute (Article 8). The two regimes run side by side; see our data protection page.
ISO/IEC 27001: the June 2027 deadline
Key entities must meet the conditions of the Montenegrin standard for information security management MEST ISO/IEC 27001, hold a certificate from an accredited body, and request periodic re-checks (Article 18(4)-(6)). The transitional deadline is 30 months from entry into force (Article 73). With publication on 27 November 2024 and entry into force on the eighth day after publication (Article 81), that runs to June 2027.
Certification is a supervised obligation, not a paper one: the Agency's supervisors are empowered to check that key entities hold the certificate and have requested the periodic re-check (Articles 40(9) and 53(3)), and failing either is a fine of €500 to €20,000 (Article 68(1), items 2 and 3). An important entity is not required to certify, but must still apply all the measures in Articles 11 to 16.
Supervision
The Cyber Security Agency carries out expert supervision of bodies and entities other than state administration bodies (Article 6). Its supervisors may check the Article 11-15 measures at any covered entity, the Article 16 measures at key and important entities, and certification at key entities (Article 53). The entity must give access to premises, computer equipment and devices and hand over the requested data and documents without delay (Article 54). Minutes go to the entity within three days (Article 55); the supervisor sets a deadline to fix irregularities, and if they are not fixed the Agency's director orders measures by decision, which can be challenged in an administrative dispute (Article 56). The Agency may also scan the systems of key and important entities proactively — with their prior consent (Article 40(3)).
Excluded from the Act altogether are the defence ministry, the Army, the National Security Agency, the police, the Parliament and the Central Bank of Montenegro, and data protected under the classified-information legislation (Article 7). Financial-sector firms should also check the separate digital operational resilience act for the financial sector ("Sl. list CG" 14/26), which we cover on our AI law page; this page does not resolve how the two statutes interact for a given bank or payment institution.
Fines at a glance
| Breach | Company | Responsible person | Article |
|---|---|---|---|
| Key entity: Article 11-16 measures not applied, no ISO/IEC 27001 certificate, no periodic re-check, changes not reported | €500–€20,000 | €30–€1,500 | 68 |
| Important entity: Article 11-16 measures not applied, changes not reported | €500–€10,000 | €30–€1,500 | 69 |
| Any legal person: Article 11-15 measures not applied, no designated employee, data request not answered in 7 days, changes not reported in 14 days, any missed incident notice or report | €500–€5,000 | €30–€1,500 | 70 |
If you are buying or running a Montenegrin company
Four questions belong in every technology-dependent file:
- Has the company received an Article 20 data request, or an Article 23 notice that it has been designated? The List is classified, so the answer must come from the company.
- Who is the employee appointed under Article 18(3), and where are the Article 11-15 measures written down?
- Where are the monthly Article 29 reports and any Article 30-34 notifications, and were they filed on time?
- For a key entity, where is the certification project against the June 2027 deadline?
How we work on these files
We map a specific company against Articles 2, 4 and 19, write the Article 18 measures into the documents an inspector will ask for, set up the incident clock so that the 24-hour notice and the 72-hour reports are not improvised during an incident, and run the questions above in diligence. Technology contracts and supply-chain terms, including what a supplier owes you when an incident starts in its systems, sit with our IT law practice; the personal-data side sits with data protection.
If you operate systems in Montenegro, or are buying a company that does, send us the list of systems, the sector the business falls into and any correspondence from a ministry or the Agency. We will tell you which tier you are in, what the Act already requires of you today, and what has to be ready by June 2027.




