Law on Information Security, Cyber Threat and Incident Reporting
Law on Information Security, Arts. 28 to 37
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 5 December 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This binds you on the same broad terms as this jurisdiction's general security-measures row: any business, other legal entity or natural person that accesses or processes data through a network and information system in Montenegro, regardless of sector, size, or essential or important entity designation (Article 2).
- Where a cyber threat or incident has no effect on the continuity of your service, report it once a month to the Cybersecurity Agency (Article 29).
- Where a cyber threat or incident could significantly affect the continuity of your service, submit an initial notification to the Cybersecurity Agency within 24 hours of becoming aware of it, on the prescribed form (Article 30).
- For an incident the Agency rates medium, submit a first report within 72 hours of your initial notification, a further report without delay on any new development, continuing reports every 72 hours while the incident lasts, and a final report within 30 days of resolving it (Article 33).
- For an incident the Agency rates high, follow the same reporting sequence on a tighter clock: continuing reports every 24 hours while the incident lasts (Article 34).
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 70 frames a reporting-clock violation as an administrative misdemeanor (“prekršaj”) carrying only the fine described in penalty_structure, and creates no separate criminal offence.
Penalty structure
Article 70(1) items 5 to 15 fine the legal entity 500 to 5,000 EUR, the same range as this jurisdiction's general security-measures row, for missing the monthly report, the 24-hour initial notification, or any of the medium- or high-incident follow-up, continuing or final report clocks; the responsible individual within that entity is fined a further 30 to 1,500 EUR for the same violation, and a repeat violation can add a 3-to-6-month suspension of the entity's professional activity. This range applies regardless of essential or important entity designation, because Chapter IV's reporting duties are not gated by it.
- Rule
- Fixed only
- As of
- 18 September 2026
- Minimum
- 500
- Currency
- EUR
- Fixed cap
- 5,000
Who enforces it
Enforcement body
The Cybersecurity Agency of Montenegro (Agencija za sajber bezbjednost) for every organ or other entity outside the state administration (Article 6); the CIRT of the state administration, within the Ministry of Public Administration, Digital Society and Media, for a state administration body (Article 5).
Settledness
- As of
- 18 September 2026
- Guidance link
- https://www.gov.me/en/asb
- Guidance body
- Agencija za sajber bezbjednost Crne Gore (Cybersecurity Agency of Montenegro)
- Open questions
- Article 30 counts the 24-hour initial-notification clock from the moment an organ or other entity becomes aware of a cyber threat or incident, so does an entity that first learns of an incident from a downstream customer's report satisfy that clock by notifying within 24 hours of the customer's report rather than of the incident's own occurrence?
What it reaches
Obligation class
Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 28 requires every organ and other entity to assess the impact of a cyber threat or incident on the continuity of the services it provides, by the number of users affected, the duration, and the geographic reach. Article 29 requires an assessment of no impact to be reported once a month to the Cybersecurity Agency, or to the Government CIRT for a state administration body.
Article 30 requires an assessment of possible significant impact to be reported within 24 hours of becoming aware of it, on a prescribed form; the Agency or CIRT then rates the incident low, medium or high under Article 31.
A medium-rated incident carries a 72-hour first report, further reports without delay on any new development, continuing reports every 72 hours while it lasts, and a final report within 30 days of resolution (Article 33); a high-rated incident carries the same sequence on continuing reports every 24 hours instead (Article 34), and a high-rated incident the Agency and CIRT cannot resolve within ten days can be escalated to a Government-declared cyber crisis under Article 35.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official Gazette of Montenegro (“Službeni list Crne Gore”), No. 113/2024, 27 November 2024