Law / Albania

Law No. 25/2024, On Cybersecurity

Law No. 25/2024 (Ligj Nr. 25/2024), 21 March 2024, "Për sigurinë kibernetike" ("On Cybersecurity"), Fletorja Zyrtare No. 67/2024, p. 7767

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 3 May 2024.

A sector security regimes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This binds a subject named in Annexes I or II of the law as administering a critical or important information infrastructure; the National Authority for Cybersecurity's own presentation of those Annexes lists digital service providers among the sectors reached, alongside energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, business to business ICT service management, public administration, space, education, tourism, postal and courier services, waste management, chemicals, food and manufacturing; only the digital service provider class is flagged here, because none of the other named sectors, nor the high criticality versus other critical designation itself, is expressed by an activity in this vocabulary.
  • Register your critical or important information infrastructure with the National Authority for Cybersecurity (AKSK), establish a Computer Security Incident Response Team and a single point of contact for AKSK and other CSIRTs, and implement the technical, organisational and operational risk management measures a Council of Ministers methodology sets for your designated category.
  • Report a significant or substantial cybersecurity incident to AKSK and the relevant CSIRTs, and inform the public or affected users where the incident reaches them; cooperate with AKSK and other operators in sharing cybersecurity threat, vulnerability and incident information. AKSK's own incident categorisation and log retention regulations set the reporting clock and severity thresholds that apply to your designated category.
  • Where your organisation processes personal data in the course of these duties, do so under Albania's personal data protection legislation; this law's security measures duty is separate from, and does not substitute for, a breach notification duty to Albania's data protection authority under Law No. 124/2024.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

PwC's client alert reports that the law provides criminal sanctions for acts that endanger the security of networks and information systems, such as unauthorized access, interception, interference, damage or destruction; those are offences committed against a system by an intruder rather than a compliance failure by the bound operator, so criminal exposure is coded false for this instrument and the intrusion offences stay with this jurisdiction's scraping topic.

Penalty structure

PwC's client alert reports this range for a violation of the law generally, varying by the type and severity of the violation, without naming the enabling article; the penalty chapter's own text was not confirmed to verify the figure or to disaggregate it by violation type.

Rule
Fixed only
As of
18 September 2026
Minimum
200,000
Currency
ALL
Fixed cap
10,000,000

Who enforces it

Enforcement body

The National Authority for Cybersecurity (Autoriteti Kombëtar për Sigurinë Kibernetike, AKSK), a public legal entity under the Prime Minister that serves as the main regulator and supervisor of cybersecurity, the national single point of contact, and the National CSIRT and CERT.

Settledness

As of
18 September 2026
Open questions
  • Given the primary Fletorja Zyrtare text available here stops at Article 5 and the Annexes I and II were not confirmed against the statute's own text, do the law's own Chapter II through V articles confirm the Authority's presentation-slide account of the sector list, the operator duties, and the numeric clock for reporting an incident to the Authority and the sectoral CSIRTs?
  • Given PwC's client alert states the 200,000 to 10,000,000 Albanian Lek administrative fine range without naming the enabling article, does the law's own penalty chapter confirm that range and tie it to specific violation classes rather than a single undifferentiated band?

What it reaches

Obligation class

Security, Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Law No. 25/2024 sets the rights and duties of public and private subjects that administer information infrastructure, communication networks and their systems whose compromise would affect the health, safety or economic wellbeing of the public or the effective functioning of the economy.

The law also names the National Authority for Cybersecurity as the single point of contact for cybersecurity matters, establishes the National CSIRT, CERT and sectoral CSIRTs, and requires a subject named in Annexes I or II to comply with mandatory cybersecurity risk management measures and to report cybersecurity incidents.

Per PwC's published account of the law, a bound operator must register its critical or important information infrastructure with the Authority, establish its own Computer Security Incident Response Team, implement the technical, organisational and operational risk management measures the Council of Ministers sets, report a significant or substantial incident to the Authority and the relevant CSIRTs, inform affected users, and cooperate with the Authority and other operators on sharing threat and incident information.

The National Authority for Cybersecurity's own presentation of the law's Annexes lists digital service providers among the sectors it reaches, alongside energy, transport, banking, financial market infrastructure, health, water supply, digital infrastructure, public administration and several other named sectors. PwC's client alert reports an administrative fine of 200,000 to 10,000,000 Albanian Lek for a violation of the law, varying with the type and severity of the violation.

The law entered into force on 3 May 2024, fifteen days after its publication, and PwC reports a 24 month period from that date for operators to bring their practices into compliance. The measures, reporting and penalty articles themselves are not confirmed against the primary Fletorja Zyrtare text here, whose paginated viewer rendered only the law's opening chapter, so this instrument's operative content beyond Article 1 rests on the Authority's own presentation and on PwC's client alert.

When LexLint raises it

  • operates_social_platform

Read the law

Primary text: Fletorja Zyrtare (Albania's Official Gazette) via qbz.gov.al
No. 67/2024, page 7767, covering Chapter I (Articles 1 to 5) of the law in the pages the document viewer displayed. The sector list, operator duties and administrative fine range beyond Chapter I are documented from the National Authority for Cybersecurity's own presentation (aksk.gov.al) and PwC Albania's client alert (pwc.com), neither of which is the statute's own text for those provisions.

Back to the example  ·  Lint your app