Law / Montenegro

Law on Information Security, Essential and Important Entities

Law on Information Security, Arts. 4, 16, 18(4) to (6), and 19 to 27

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 5 December 2024.

A sector security regimes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This reaches you only where the Government of Montenegro has designated your organisation an essential or important entity on a sector list adopted under Articles 19 to 22. The digital-infrastructure essential-entity sector (an internet exchange point, a DNS or top-level-domain registry, a cloud computing, data centre, content delivery network or qualified trust service provider) and the online-marketplace important-entity sector are the digital categories closest to a software or platform business, so only that slice is flagged here; the ICT-service-management essential-entity sector and the wider non-digital sectors (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, public administration and space among essential entities; postal and courier services, waste management, chemicals, food, manufacturing and research among important entities), together with the essential and important entity designation itself, are a role no activity in this vocabulary expresses, and are not raised here on that account.
  • If designated, adopt a cyber-security risk and security analysis, an incident-handling policy, a business-continuity and cyber-crisis plan, a supply-chain security act and system-governance acts, apply cryptographic protection where your work requires it, and assess the effectiveness of these measures (Article 16).
  • If designated an essential entity, obtain a certificate of compliance with the Montenegrin standard MEST ISO/IEC 27001 from an accredited body within 30 months of 5 December 2024, and request a periodic re-verification from that body afterward (Article 18(4) to (6) and Article 73).
  • Report any change to your registration details to the competent ministry within 14 days of the change (Article 26).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Articles 68 and 69 frame a violation as an administrative misdemeanor (“prekršaj”) carrying only the fines described in penalty_structure, and create no separate criminal offence.

Penalty structure

Article 68(1) fines an essential entity 500 to 20,000 EUR, and Article 69(1) fines an important entity 500 to 10,000 EUR, each for failing to apply the Article 11 to 16 measures, failing the MEST ISO/IEC 27001 certification or periodic-review duty (essential entities only), or failing to notify a change of registration details; both Articles fine the responsible individual within the entity a further 30 to 1,500 EUR for the same violation.

Rule
Fixed only
As of
18 September 2026
Minimum
500
Currency
EUR
Fixed cap
20,000

Who enforces it

Enforcement body

The Cybersecurity Agency of Montenegro (Agencija za sajber bezbjednost), through supervisors authorized under Article 52, for every essential and important entity outside the state administration; the Ministry of Public Administration, Digital Society and Media, through an inspector for information society services, for a state administration body designated essential or important (Articles 64 to 67).

Settledness

As of
18 September 2026
Guidance link
https://www.gov.me/en/asb
Guidance body
Agencija za sajber bezbjednost Crne Gore (Cybersecurity Agency of Montenegro)
Open questions
Does the important-entity digital-provider sector under Article 19, naming only providers of online marketplace services, also reach an online search engine or a social-networking-services platform the way Annex II of the NIS2 Directive does?

What it reaches

Obligation class

Security, Governance, DPIA

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 4 defines an essential entity as an organ or other entity that applies information and communication technology to deliver a service so significant to life, health, citizen safety or state functioning that its interruption or destruction would endanger them, and an important entity as one delivering a service whose interruption would only impair state functioning; both definitions apply regardless of the entity's size.

Article 19 places essential entities within eleven named sectors (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space) and important entities within seven others (postal and courier services, waste management, chemicals manufacture, food production, manufacturing of medical devices, electronics, electrical equipment, machinery or motor vehicles, online marketplace services, and research).

Articles 20 to 26 set the mechanics for the Government to adopt and maintain a Government-approved List of essential and important entities from sectoral proposals the competent ministries compile.

A designated entity carries the enhanced risk-management measures of Article 16 (a risk and security analysis, an incident-handling policy, a business-continuity and cyber-crisis plan, a supply-chain security act, system-governance acts, cryptographic protection where required, and an effectiveness assessment of these measures) on top of the general measures this jurisdiction's companion row describes, and, if designated an essential entity, must obtain a certificate of compliance with the Montenegrin standard MEST ISO/IEC 27001 from an accredited body within 30 months of the law's entry into force and request a periodic re-verification afterward (Article 18(4) to (6) and Article 73).

The Cybersecurity Agency launched its first supervision cycle in July 2026, sending questionnaires to designated essential and important entities and completing an on-site inspection of at least one essential entity, and reported that essential entities showed higher self-assessed compliance than important entities.

When LexLint raises it

  • operates_social_platform

Read the law

Official Gazette of Montenegro (“Službeni list Crne Gore”), No. 113/2024, 27 November 2024

Back to the example  ·  Lint your app