Albania enacted Law No. 25/2024 (Ligj Nr. 25/2024) "On Cybersecurity" ("Për sigurinë kibernetike"), adopted by the Assembly on 21 March 2024, promulgated by presidential decree on 16 April 2024, and published in the Official Gazette (Fletorja Zyrtare) No. 67 of 18 April 2024 at page 7767. The law's own text states that it partially transposes Directive (EU) 2022/2555 (NIS2).
Article 1 sets the law's subject matter as the rights and duties of public and private subjects that administer information infrastructure, communication networks and their systems, and names as its further contents the responsible cybersecurity authority and single point of contact, the incident response teams (the National CSIRT, CERT, and sectoral CSIRTs), the authority that drafts the National Cybersecurity Strategy, the security and risk management measures binding on subjects named in Annexes I and II, the duty of those subjects to report cybersecurity incidents, and the rules for sharing cybersecurity information.
Article 3 confines the law's application to public and private subjects that administer information systems and networks as defined in Annexes I and II. The National Authority for Cybersecurity (Autoriteti Kombëtar për Sigurinë Kibernetike, AKSK) presents itself as the law's designated regulator, national single point of contact, and national CSIRT and CERT.
AKSK's own presentation of the law's Annexes lists energy, transport, banking, financial market infrastructure, health, classified information handling tied to public security, drinking water supply, wastewater, digital infrastructure, business to business ICT service management, public administration, space, education and tourism as high criticality sectors, and postal and courier services, waste management, chemicals, food, manufacturing, and digital service providers as further critical sectors.
Per AKSK's and PwC's published accounts, a bound operator must register its critical or important information infrastructure with AKSK, establish a Computer Security Incident Response Team and a point of contact for AKSK and other CSIRTs, implement the technical, organisational and operational risk management measures a Council of Ministers methodology sets, report a significant or substantial cybersecurity incident to AKSK and the relevant CSIRTs and inform affected users where the incident reaches them, and cooperate with AKSK and other operators on sharing cybersecurity information.
PwC's client alert reports an administrative fine of 200,000 to 10,000,000 Albanian Lek for a violation of the law, varying with the type and severity of the violation, though the penalty article's own text was not confirmed to verify that figure or name the enabling article.
The law entered into force on 3 May 2024, fifteen days after publication, a date AKSK's own presentation and PwC's client alert both state, and PwC reports operators had a 24 month period from that date, ending in May 2026, to bring their practices into compliance.
PwC's client alert also reports that the law provides criminal sanctions for unauthorised access, interception, interference, damage or destruction directed against a network or information system, a duty on an intruder rather than on the operator, which stays with this jurisdiction's scraping topic computer misuse family and Criminal Code Article 192/b, already filed there, rather than being restated here.
Article 4 requires that personal data processing under the law follow Albania's data protection legislation, and Law No. 124/2024 On the Protection of Personal Data, this jurisdiction's privacy topic comprehensive regime, is the kind of General Data Protection Regulation (GDPR) style act that ordinarily carries its own security of processing article as that regime's own clause, though neither topic's research has independently confirmed such an article's text, so nothing is restated here. qbz.gov.al's own document viewer serves the Official Gazette through a paginated component, and the copy available showed only Chapter I (Articles 1 through 5), general provisions on subject matter, purpose, scope and principles, and did not advance to later pages despite several page-target attempts, so the full text of Annexes I and II and the operative chapters on security measures, incident reporting and penalties are not confirmed against the statute's own text here.
AKSK's separate certificate authority domain, cesk.gov.al, answered with an expired TLS certificate rather than any content.
AKSK's presentation also names three subordinate acts already issued under the law: a Council of Ministers methodology for identifying critical and important information infrastructure operators, VKM No. 683 of 6 November 2024; a Director General regulation categorising cybersecurity incidents, Order No. 299 of 21 August 2024; and a Director General regulation on retention periods for cybersecurity incident logs, Order No. 408 of 7 November 2024, none of which were located in full text. AKSK further reports a National Cybersecurity Strategy and Action Plan 2025 to 2030 as still in preparation.