Technology

Montenegro Rewrote Its Electronic Signature Law in July 2026 — and Deferred the Part Foreign Companies Need

Act 92/2026 entered into force on 8 July 2026 — but Article 64, the automatic recognition of EU qualified signatures, waits for accession.

Rohat Kahraman· 5 September 2026Updated · 5 September 2026
Abstract cover for a guide to Montenegro's 2026 electronic identification and trust services act

Foreign companies dealing with Montenegro have been running into the same wall for years: a signature that is unquestionably valid at home is treated as nothing on arrival. The usual explanations — bureaucratic conservatism, an outdated statute — were never the real one, and as of this summer they are certainly not.

The statute is new. What blocks the foreign signature is written into it deliberately, in a provision that has been enacted but does not yet apply.

All article numbers below come from the Zakon o elektronskoj identifikaciji i uslugama povjerenja, adopted by the Skupština on 26 June 2026, published in "Službeni list CG" br. 92/2026 of 30 June 2026 and in force since 8 July 2026, read from the promulgated text on 5 September 2026. General information, not advice on a specific transaction.

First, the statute you may have researched no longer exists

Article 122 repeals the Zakon o elektronskoj identifikaciji i elektronskom potpisu ("Službeni list CG" br. 31/17 and 72/19) with effect from the new Act's entry into force. Any memo, template or internal policy that cites 31/17 is citing a repealed act, and the article numbering has changed completely.

Article 123 sets entry into force on the eighth day after publication — 8 July 2026. The Act states that it is aligned with Regulation (EU) No 910/2014 and with Regulation (EU) 2024/1183 on the European digital identity framework, which is why its structure will look familiar to anyone who works with eIDAS. The familiarity is where the trouble starts, because the parts that make eIDAS work across borders are precisely the parts Montenegro has held back.

Three tiers of signature, and what each one actually does

TierDefinitionLegal effect
Electronic signature (Art. 65(1))Data in electronic form attached to, or logically associated with, other electronic data and used by the signatory to signCannot be denied legal effect or admissibility as evidence in court merely for being electronic or for not meeting the qualified requirements (Art. 67(1))
Advanced electronic signature (Arts. 65(2), 66)Uniquely linked to the signatory, capable of identifying them, created with data the signatory can use under their sole control with a high level of confidence, and linked to the signed data so any later change is detectableSame non-discrimination rule; an authority or legal person may not refuse an electronic document bearing it solely because it is electronic (Art. 67(2))
Qualified electronic signature (Art. 65(3))An advanced signature created by a qualified signature creation device and based on a qualified certificateHas the same legal effect as a handwritten signature (Art. 68)

Read Article 67 carefully, because it is weaker than it looks. Article 67(1) is a rule of evidence: a court may not throw out an electronic signature just because it is electronic or unqualified. It does not make that signature equivalent to a handwritten one. Article 67(2) prevents an authority or legal person from refusing to receive an electronic document on the ground of its form. Neither provision tells you the document was validly executed.

Only Article 68 does that, and only for the qualified tier.

Two limits that survive the new Act

Article 3(2) is the provision most likely to defeat a plan built around electronic execution: this Act does not affect the conclusion and validity of contracts that have special conditions relating to the form of their conclusion, as laid down by law. Where another statute prescribes a form — notarial processing, solemnisation, registration — the electronic signature statute leaves that requirement standing. A qualified signature is the equal of a handwritten one under Article 68; it is not the equal of a notarial act. For Montenegrin property and company transactions, that distinction decides the file.

Article 3(1) carves out trust services used exclusively in closed systems between a defined group of participants which do not affect third parties, where a law or ratified international treaty so provides. Internal group signing platforms may sit outside the Act entirely — which is convenient until the document has to be produced to a third party.

And Article 2 sets the Act's reach: it applies to electronic identification systems, digital identity wallets and trust service providers registered in Montenegro. That framing is the key to the cross-border problem.

The deferral list, and why your Italian or Estonian signature is not automatically enough

The Act's own commencement note defers a specific list of provisions to the date of Montenegro's accession to the European Union: Articles 7 and 29, Article 30(1), (2) and (3), Articles 31, 32 and 33, Articles 41 and 42, Article 44(1), Articles 45 to 49, Article 56(6), Article 61, Article 63(1), and Articles 64, 69, 75, 83, 97, 108, 109 and 110.

Two entries on that list matter to every foreign counterparty.

Article 64 is the automatic recognition provision. It states that a qualified electronic signature and a qualified electronic seal based on a qualified certificate issued in an EU member state are recognised as qualified in Montenegro; that qualified signature creation devices certified in an EU member state are recognised as such here; and that qualified certificates and qualified remote signature management services provided in a member state are recognised in the same way. That is the eIDAS mutual-recognition effect, transposed in full — and switched on only at accession.

Article 63(1) is the general cross-border rule for EU-established trust service providers, and it is deferred on the same basis. Article 63(2), which is not deferred, covers providers established in a non-EU state: their trust services have the same legal effect as qualified services provided by qualified Montenegrin providers when they are recognised on the basis of an international mutual-recognition agreement founded on reciprocity, whose implementing acts form an integral part of it. Article 63(3) requires those agreements and implementing acts to secure compliance with the conditions for qualified providers.

So the operative position today is narrow. Recognition of a foreign qualified signature runs through Article 63(2) and requires a reciprocity-based international agreement. We have not identified a published agreement of that kind in force for Montenegro, and we are not going to assert one exists or does not exist on the strength of an absence of search results — it is a question to put to the competent ministry for the specific certificate and provider involved, before a signing date is fixed.

Article 69, also deferred, would have obliged authorities to accept advanced and qualified signatures in at least the formats published by the European Commission when an electronic service requires one. Until accession, format acceptance for public-sector e-services is not governed by that provision.

How to check a provider, and who pays when it goes wrong

Article 60(1) requires the Ministry to maintain and publish a Trust List of trust service providers, covering both qualified and non-qualified providers together with information on the services they supply. Article 60(2) requires it to be kept in a form suitable for automatic processing and published on the Ministry's website over a secure channel; Article 60(3) requires it to be maintained in accordance with international standards and signed with an advanced electronic signature or sealed with an advanced electronic seal; Article 60(4) leaves the detailed manner of keeping it to the Ministry. That list — not a provider's own marketing — is where qualified status is confirmed.

Article 61, which would let a qualified provider entered on the Trust List use the EU trust mark, is on the deferral list and therefore does not operate before accession. A provider displaying an EU trust mark in connection with Montenegrin qualified status is not relying on Article 61 as it currently stands.

Article 62 then allocates the loss, and it does so asymmetrically:

  • Article 62(1) makes a trust service provider liable for damage caused intentionally or negligently to any natural or legal person where it has not acted in accordance with the Act, and Article 62(2) gives the injured party a right to compensation.
  • Article 62(3) puts the burden of proving intent or negligence of a non-qualified provider on the claimant.
  • Article 62(4) reverses it for a qualified provider: intent or negligence is presumed, unless that provider proves the damage arose without either.
  • Article 62(5) gives every provider a defence: one that has informed its users in advance of limitations on the use of its services is not liable for damage arising from use that exceeds those limits.

The combination is worth pricing into a provider decision. Choosing a qualified provider does not only buy Article 68 equivalence; it also moves the burden of proof onto the provider if something fails. And the Article 62(5) defence is a reason to read the provider's stated usage limits before relying on a certificate for a transaction value or a use case it was never offered for.

The requirement that works the other way round

One pair of provisions runs in the opposite direction. Article 53(1) point 12 requires a qualified trust service provider to ensure that the premises and equipment used to provide qualified trust services are located on the territory of Montenegro. Article 53(1) point 13 requires that data and documents held in its information system are not stored on ICT infrastructure outside Montenegro, unless a special law or a ratified international treaty provides otherwise.

Both of those apply until the date of accession — a temporary localisation regime, not a permanent one. The practical effect while it lasts is that a qualified trust service provider serving the Montenegrin market cannot run the service from foreign premises or store the underlying data abroad, which narrows the field of providers a company can lawfully rely on for qualified status here, and which has to be squared with any group-wide cloud policy.

What this means when you actually have to sign something

For a foreign company the sequence is now reasonably clear.

Establish which tier the transaction needs. If the counterparty, a register or a public authority requires handwritten-equivalent execution, only the qualified tier under Article 68 delivers it; the non-discrimination rules in Article 67 will not.

Then establish where the certificate comes from. A qualified certificate from a provider registered in Montenegro operates inside Article 2 and Article 68 without more. A qualified certificate issued in an EU member state does not get the automatic Article 64 treatment yet, and the fallback route in Article 63(2) depends on a reciprocity agreement that has to be verified rather than assumed.

Then check whether any special form requirement applies at all, because Article 3(2) means the whole analysis can be moot. Where the underlying statute demands a notarial form, an electronic signature of any tier does not substitute for it — the position we set out in the notary's role in property and company deals.

And build the timetable around it. The realistic answer for a foreign signatory who needs handwritten-equivalent effect in Montenegro today is either a Montenegrin qualified certificate or a properly drafted power of attorney executed in the ordinary way — not a last-minute assumption that the certificate already on the laptop will be accepted.

Before your next Montenegrin signing date

If a transaction, filing or contract is due to be signed electronically with a Montenegrin counterparty, authority or register, send us the certificate details, the issuing provider and the underlying instrument, and we will identify which tier Article 65 puts the signature in, whether Article 68 gives it handwritten-equivalent effect, whether Article 3(2) means the form question is decided by a different statute altogether, and what Article 63(2) requires before a foreign qualified certificate can be relied on. The contract-drafting layer for technology deals is in the four clauses in your SaaS contract, the entity-level signing questions in branch or subsidiary, and the data-location side of Article 53 connects to cross-border data transfers. How we run technology files sits with our IT law practice.

Frequently asked questions

Is an electronic signature legally binding in Montenegro?

It depends on the tier. Article 68 gives a qualified electronic signature the same legal effect as a handwritten signature. Article 67(1) provides only that an electronic signature cannot be denied legal effect or admissibility as evidence in court merely for being electronic or for not meeting the qualified requirements — which is an evidentiary rule, not equivalence.

Which law governs electronic signatures in Montenegro now?

The Zakon o elektronskoj identifikaciji i uslugama povjerenja, "Službeni list CG" br. 92/2026 of 30 June 2026, in force since 8 July 2026. Article 122 repealed the previous Act ("Službeni list CG" br. 31/17 and 72/19) on that date, and the article numbering changed.

Will my EU qualified electronic signature be accepted in Montenegro?

Not automatically, yet. Article 64 provides for recognition of qualified signatures and certificates issued in EU member states, but it is on the list of provisions that apply only from the date of Montenegro's accession to the European Union. Article 63(1), the general rule for EU-established providers, is deferred on the same basis.

Is there any route for a foreign certificate today?

Article 63(2), which is not deferred, gives trust services from providers established in a non-EU state the same effect as qualified Montenegrin services where they are recognised under an international mutual-recognition agreement based on reciprocity, with implementing acts forming part of it. Whether such an agreement is in force for a particular state and provider has to be verified with the competent ministry rather than assumed.

Can I sign a Montenegrin property purchase electronically?

Article 3(2) provides that the Act does not affect the conclusion and validity of contracts subject to special statutory conditions as to form. Where another statute prescribes a notarial form, an electronic signature does not replace it, whatever its tier under Article 65.

What is the difference between an advanced and a qualified signature?

Article 66 sets four conditions for an advanced signature: it is uniquely linked to the signatory, can identify them, is created using data the signatory can use with a high level of confidence under their sole control, and is linked to the data so any later change is detectable. Article 65(3) makes a signature qualified where it is an advanced signature created by a qualified creation device and based on a qualified certificate — and only that tier gets Article 68's handwritten equivalence.

Can a Montenegrin authority refuse a document because it is electronic?

Article 67(2) provides that an authority or a legal person may not refuse to accept an electronic document bearing an electronic or advanced electronic signature solely because it is in electronic form. That prevents refusal on the ground of form; it does not decide whether the signature had the effect the transaction required.

Can a qualified trust service provider host our data abroad?

Not while the transitional rule lasts. Article 53(1) point 12 requires the premises and equipment used for qualified trust services to be located in Montenegro, and point 13 prohibits storing the information system's data and documents on ICT infrastructure outside Montenegro unless a special law or ratified treaty provides otherwise. Both apply until the date of Montenegro's accession to the European Union.