Technology

Montenegro's Cybersecurity Law: What the 2024 Information Security Act Requires of Companies

Montenegro's 2024 Information Security Act reaches any company running network systems: 24-hour incident notices, ISO 27001 by June 2027, fines.

Rohat Kahraman· 11 September 2026Updated · 11 September 2026
Editorial dusk illustration over the Montenegrin coast representing network security obligations under the 2024 Information Security Act

Montenegro replaced its 2010 information security statute with a new Law on Information Security (Zakon o informacionoj bezbjednosti), published in the Official Gazette of Montenegro no. 113/2024 on 27 November 2024 and in force from the eighth day after publication. It aligns Montenegrin law with the EU's NIS2 Directive (Directive (EU) 2022/2555), created a Cyber Security Agency (Agencija za sajber bezbjednost) to supervise it, and — this is the part most foreign companies miss — it does not stop at banks, utilities and telecoms.

The Act applies to companies, other legal persons and natural persons that access or handle data and use and manage a network and information system (Article 2). If your Montenegrin company runs its own servers, cloud accounts, a booking platform or an office network, you are inside it. What changes with the tier you fall into is how much you must do, whether you need an ISO/IEC 27001 certificate, and which fine applies.

Sources, checked 11 September 2026: the Act as published in "Sl. list CG" 113/2024, read from the Official Gazette's own page images (Articles 1–81); the gazette record lists no amending act. General information about Montenegrin law, not advice on a particular system or incident.

Three tiers, and the bottom one is almost everyone

TierWhoWhat the Act requiresFine for the company
Key entity (ključni subjekt)Designated by the Government in the listed sectors (Articles 4(1), 19(1))All security measures in Articles 11 to 16; ISO/IEC 27001 certificate and periodic re-checks (Article 18(1), (4)-(6))€500 to €20,000 (Article 68)
Important entity (važni subjekt)Designated by the Government in the listed sectors (Articles 4(2), 19(2))All security measures in Articles 11 to 16 (Article 18(1))€500 to €10,000 (Article 69)
Every other company using a network and information systemAny "other entity" under Article 2Security measures in Articles 11 to 15; a designated employee; incident assessment and reporting (Articles 18(2)-(3), 28-34)€500 to €5,000 (Article 70)

The responsible person within the company faces €30 to €1,500 in each tier (Articles 68(2), 69(2), 70(2)), and repeating a breach listed in Article 70 can lead to a ban on carrying on the profession, activity or duty for three to six months (Article 70(3)).

Size does not take you out

Montenegro's Act does not use company size to decide who is in scope. It defines key and important entities by what they do and what would happen if they stopped — and says expressly that designation applies regardless of size within the meaning of the accounting legislation (Article 4(1) and (2)). A small company that runs something the state depends on can be designated. And the bottom tier has no size filter at all: Article 18(2) obliges bodies and other entities that are not designated to apply the measures in Articles 11 to 15, and Article 18(3) obliges all of them to appoint an employee to monitor those measures.

The sectors

Key entities — sectors (Article 19(1))Important entities — sectors (Article 19(2))
Energy: electricity, district heating and cooling, oil, gas, hydrogenPostal and courier services
Transport: air, rail, maritime, roadWaste management
Banking (credit institutions)Manufacture and distribution of chemicals
Financial market infrastructureFood production, processing and distribution
Health: primary, secondary and tertiary care, reference laboratories, medicines researchManufacturing: medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment
Drinking waterDigital providers: online marketplaces
Waste waterResearch organisations
Digital infrastructure: internet exchange points, DNS, top-level domain registries, cloud computing, data centres, content delivery networks, qualified trust service providers, public electronic communications
ICT service management
Public administration
Space

Entities in the key-entity sectors that are not designated as key can still be designated as important if they meet the Article 4(2) criteria (Article 19(3)).

How you find out — and why a buyer cannot simply check

Designation runs through the ministries, not through an application you file.

  • The ministry responsible for the sector compiles a list of bodies and entities and asks them for data — name, seat, tax number, responsible person, official electronic address, contact phone, activity and sector (Article 20(1)-(2)). You must reply within seven days of the request and report changes within 14 days (Article 20(3)-(4)).
  • Sectoral proposals go to the Ministry, which prepares a consolidated proposal; the Government adopts the List of key and important entities (Articles 21-22). The Act gave the ministries nine months from entry into force to submit their sectoral proposals (Article 72).
  • The sector ministry must notify each designated entity within seven days of the List being adopted (Article 23), and designated entities must report changes to their registered data immediately (Article 26(1)).
  • The List, the sectoral and consolidated registers and the underlying data are classified (Article 27).

That last point matters in a transaction. You cannot confirm from a public register whether a Montenegrin target company is a key or important entity. The only reliable source is the target itself: ask for any Article 20 data request, any Article 23 notification, and the state of its Article 18 compliance and certification. The rest of the diligence sequence is in buying a Montenegrin company: the share deal.

What the security measures are

The Act frames two families of measures (Article 11): protection of data — rules for handling data, records of access and oversight of data security (Article 12) — and protection from cyber threats and incidents — physical protection, protection of the network and information system across its whole life cycle, and cyber-risk management (Articles 13-16).

Cyber-risk management is the part reserved to key and important entities (Article 16): a risk and security analysis; incident-handling rules for prevention, detection and response; a business continuity and crisis plan; an act governing supply-chain security with suppliers and service providers; acts on establishing and maintaining systems; cryptographic protection where the work requires it; and rules for assessing whether all of that works. The detailed content of the measures is set by Government decree (Article 17). The Act gave six months for the new implementing acts and kept the old ones in force until then (Article 71) — check which instrument governs your file on the day you act.

The incident clock

Every body and entity covered by the Act, not only designated ones, must assess the impact of a cyber threat or incident on the continuity of its services, using four criteria: users who could not access the service, users with significant difficulty, duration, and geographic spread (Article 28).

SituationWhat must be sent, and whenArticle
No impact on service continuityA report on those threats and incidents to the Agency once a month, and you handle them yourself29
Could significantly affect continuityInitial notification within 24 hours of learning of it, on the prescribed form30
Level setThe Agency (or, for state administration, its CIRT) classifies the incident as low, medium or high31
Medium-level incidentFirst report within 72 hours of the initial notification; a special report without delay on new facts; continuing reports every 72 hours; final report within 30 days of resolution33
High-level incidentFirst report within 72 hours; special report without delay; continuing reports every 24 hours; final report within 30 days of resolution34
Not resolved within 10 days of the initial notificationThe Ministry may propose that the Government declare a cyber crisis35

Every one of those notifications, reports and guidance notes is classified (Article 37). And each missed step — the monthly report, the 24-hour notice, each 72-hour or 24-hour report, the final report — is a separately listed misdemeanour for any legal person (Article 70(1), items 5 to 15).

Where an incident involves personal data, the Act sends you to the data protection statute (Article 8). The two regimes run side by side; see our data protection page.

ISO/IEC 27001: the June 2027 deadline

Key entities must meet the conditions of the Montenegrin standard for information security management MEST ISO/IEC 27001, hold a certificate from an accredited body, and request periodic re-checks (Article 18(4)-(6)). The transitional deadline is 30 months from entry into force (Article 73). With publication on 27 November 2024 and entry into force on the eighth day after publication (Article 81), that runs to June 2027.

Certification is a supervised obligation, not a paper one: the Agency's supervisors are empowered to check that key entities hold the certificate and have requested the periodic re-check (Articles 40(9) and 53(3)), and failing either is a fine of €500 to €20,000 (Article 68(1), items 2 and 3). An important entity is not required to certify, but must still apply all the measures in Articles 11 to 16.

Supervision

The Cyber Security Agency carries out expert supervision of bodies and entities other than state administration bodies (Article 6). Its supervisors may check the Article 11-15 measures at any covered entity, the Article 16 measures at key and important entities, and certification at key entities (Article 53). The entity must give access to premises, computer equipment and devices and hand over the requested data and documents without delay (Article 54). Minutes go to the entity within three days (Article 55); the supervisor sets a deadline to fix irregularities, and if they are not fixed the Agency's director orders measures by decision, which can be challenged in an administrative dispute (Article 56). The Agency may also scan the systems of key and important entities proactively — with their prior consent (Article 40(3)).

Excluded from the Act altogether are the defence ministry, the Army, the National Security Agency, the police, the Parliament and the Central Bank of Montenegro, and data protected under the classified-information legislation (Article 7). Financial-sector firms should also check the separate digital operational resilience act for the financial sector ("Sl. list CG" 14/26), which we cover on our AI law page; this page does not resolve how the two statutes interact for a given bank or payment institution.

Fines at a glance

BreachCompanyResponsible personArticle
Key entity: Article 11-16 measures not applied, no ISO/IEC 27001 certificate, no periodic re-check, changes not reported€500–€20,000€30–€1,50068
Important entity: Article 11-16 measures not applied, changes not reported€500–€10,000€30–€1,50069
Any legal person: Article 11-15 measures not applied, no designated employee, data request not answered in 7 days, changes not reported in 14 days, any missed incident notice or report€500–€5,000€30–€1,50070

If you are buying or running a Montenegrin company

Four questions belong in every technology-dependent file:

  1. Has the company received an Article 20 data request, or an Article 23 notice that it has been designated? The List is classified, so the answer must come from the company.
  2. Who is the employee appointed under Article 18(3), and where are the Article 11-15 measures written down?
  3. Where are the monthly Article 29 reports and any Article 30-34 notifications, and were they filed on time?
  4. For a key entity, where is the certification project against the June 2027 deadline?

How we work on these files

We map a specific company against Articles 2, 4 and 19, write the Article 18 measures into the documents an inspector will ask for, set up the incident clock so that the 24-hour notice and the 72-hour reports are not improvised during an incident, and run the questions above in diligence. Technology contracts and supply-chain terms, including what a supplier owes you when an incident starts in its systems, sit with our IT law practice; the personal-data side sits with data protection.

If you operate systems in Montenegro, or are buying a company that does, send us the list of systems, the sector the business falls into and any correspondence from a ministry or the Agency. We will tell you which tier you are in, what the Act already requires of you today, and what has to be ready by June 2027.

Legal basis

  • Zakon o informacionoj bezbjednosti (Sl. list CG 113/2024)čl. 2, 4, 18, 19, 20, 23, 27, 28-35, 68-70, 73Read from the Official Gazette page images, 11 September 2026; NIS2-aligned; repealed Sl. list CG 14/10, 40/16, 67/21Official text

Frequently asked questions

Does Montenegro's Information Security Act apply to a small company?

Yes. It applies to companies and other legal persons that use and manage a network and information system (Article 2). Companies that are not designated must still apply the measures in Articles 11 to 15 and appoint a responsible employee (Article 18(2)-(3)), and designation as a key or important entity applies regardless of size (Article 4).

What is the Cyber Security Agency in Montenegro?

The Agencija za sajber bezbjednost was created by the 2024 Act to protect the network and information systems of bodies and other entities, particularly key and important entities, and to supervise the application of the security measures, except for state administration bodies (Article 6). Its supervisors can inspect premises and equipment and require documents (Articles 53-54).

How quickly must a cyber incident be reported in Montenegro?

If it could significantly affect the continuity of your services, an initial notification must reach the Agency within 24 hours of learning of it (Article 30). For a medium or high-level incident the first report follows within 72 hours, continuing reports every 72 or 24 hours, and a final report within 30 days of resolution (Articles 33-34). Incidents with no impact are reported monthly (Article 29).

Do we need ISO/IEC 27001 certification?

Only key entities must hold a certificate against MEST ISO/IEC 27001 and request periodic re-checks (Article 18(4)-(6)), within 30 months of the Act's entry into force (Article 73) — June 2027. Important entities and other companies must apply the statutory measures but are not required to certify.

Can I check whether a company is a key or important entity?

No. The List of key and important entities and the registers are classified (Article 27). Designated entities are told by their sector ministry within seven days of the List's adoption (Article 23), so the evidence has to come from the company itself.

What are the fines under the Montenegrin cybersecurity law?

€500 to €20,000 for a key entity (Article 68), €500 to €10,000 for an important entity (Article 69) and €500 to €5,000 for any other legal person (Article 70), plus €30 to €1,500 for the responsible person. Repeating an Article 70 breach can lead to a three-to-six-month ban.