Montenegro's Law on Information Security (“Službeni list Crne Gore”, No. 113/2024, adopted by Parliament 19 November 2024 and in force since 5 December 2024) is a full transposition of the NIS2 Directive (Directive (EU) 2022/2555): the statute's own preamble footnote states it is harmonized with that Directive, and it repeals Montenegro's earlier Law on Information Security (“Službeni list CG”, Nos. 14/10, 40/16 and 67/21). It binds two overlapping classes on different terms.
First, a general baseline duty in Articles 11 to 15 and 18(1) to (3) reaches every organ of the state and every business, other legal entity or natural person that accesses or processes data, or uses and manages a network and information system, in Montenegro, with no sector or size gate: data-handling rules and access logging, physical security of the premises and devices holding the system, and protection of the confidentiality, integrity and availability of the data that system carries, plus a duty to name an employee to monitor compliance.
Second, an entity the Government designates an essential or important entity under Articles 4 and 19 to 27, sector lists tracking NIS2's own Annexes (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space for essential entities; postal and courier services, waste management, chemicals, food, manufacturing, online marketplace services and research for important entities), additionally carries the enhanced risk-management measures of Article 16 and, if an essential entity, must obtain and periodically renew a certificate of compliance with the Montenegrin standard MEST ISO/IEC 27001 from an accredited body within 30 months of the law's entry into force (Article 18(4) to (6) and Article 73).
Chapter IV (Articles 28 to 37) layers a tiered incident-reporting duty on top of both classes alike: a threat or incident with no effect on service continuity is reported monthly, one that could significantly affect continuity triggers a 24-hour initial notification, and the Cybersecurity Agency's own severity rating then sets a 72-hour or 24-hour ongoing-report clock and a 30-day final-report clock.
Of the sectors reaching a software or platform business, only the digital-infrastructure essential-entity category (an internet exchange point, a DNS or top-level-domain registry, a cloud computing, data centre, content delivery network or qualified trust service provider) and the online-marketplace important-entity category name a declarable digital service; the surrounding non-digital sectors, and the essential and important entity designation itself, are a role no activity in LexLint's current vocabulary expresses, and are recorded here rather than flagged on a guess.
The Cybersecurity Agency of Montenegro (Agencija za sajber bezbjednost), established under this law, enforces against every organ and other entity outside the state administration, and began its first supervision cycle in July 2026, issuing questionnaires to designated essential and important entities and completing an on-site inspection of at least one essential entity; the Ministry of Public Administration, Digital Society and Media enforces against state administration bodies through its own inspector and CIRT.
Every violation described here is an administrative misdemeanor (“prekršaj”) carrying a fine and never a criminal offence; Montenegro's Criminal Code Article 353 (unauthorised use of a computer or computer network), a distinct offence against a system committed by an intruder, is already this jurisdiction's scraping-topic row and is not restated here.
The law explicitly excludes the ministry responsible for defence, the Army of Montenegro, the Agency for National Security, the police unit of the interior ministry, Parliament, the Central Bank of Montenegro, and data whose security is governed by the classified-data law (Article 7); whether the Central Bank of Montenegro has issued separate binding cybersecurity or IT-risk directives for the banks it licenses is not confirmed in the primary text consulted here.
Personal data handled through a network or information system is carved out to Montenegro's Law on Personal Data Protection by this law's own Article 8, which is this jurisdiction's privacy-topic row and is not restated here.
Montenegro is a candidate for European Union accession rather than a member state, so the directly applicable Cyber Resilience Act (Regulation (EU) 2024/2847) does not reach Montenegro on its own force, and no Montenegrin instrument located here sets a security requirement a connected device or software product must meet to be placed on the market, independent of that Regulation.