Law / Serbia

Law on Information Security, ICT Systems of Special Importance and Security Measures

Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 5-12

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 9 months, effective 1 January 2026.

A sector security regimes rule binding public and private bodies.

As of 18 September 2026.

What it requires

  • This duty reaches you if the Ministry responsible for information security classifies your information and communication (IKT) system as a priority or an important ICT system of special importance; classification is automatic by sector for a list Articles 5 and 6 set out, which includes, among important systems, a business that provides an information society service under Serbia's e-commerce law, and the Government has not yet issued the bylaw that is to add general and sectoral criteria, including a size threshold, for either tier.
  • Apply for registration of your ICT system in the Ministry's registry of priority and important ICT systems.
  • Adopt a risk-assessment act for the ICT system you operate, covering your exposure to risk, your size as an operator, the likelihood and severity of an incident, and its potential social and economic impact, and revise the act at least once a year.
  • Adopt a security act built on that risk-assessment act, setting the principles, methods and procedures for reaching and keeping an adequate level of system security and the authority and responsibility for security and resources, and check your applied protection measures against it at least once a year, alone or with outside experts, producing a report on the check.
  • Take technical, operational, organisational and physical protection measures across the areas Article 10 lists, including multi-factor authentication or a continuous-authentication solution, secured voice, video and text communication, and secured communication channels for emergencies.
  • If your ICT system is a bank or a financial-market institution supervised by the National Bank of Serbia or the Securities Commission, also follow the sector-specific information-security rules those regulators issue under this law instead of relying on Article 10 alone.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The sanction Article 50 and Article 51 set for these duties is a misdemeanor fine (novčana kazna za prekršaj) under Serbia's minor-offenses framework, not a criminal offence (krivično delo) under the Criminal Code; a full read of the law's penalty chapter (Arts. 50-53) found no provision making a failure of these duties a criminal offence.

Penalty structure

Article 50: a legal entity that is a priority-system operator faces a misdemeanor fine of 50,000 to 2,000,000 dinars for failing to register, adopt a risk-assessment act, adopt a security act, apply the measures the security act sets, check compliance with the security act, submit required statistics, or comply with an information-security inspector's order within its deadline; a natural person operating as a registered subject faces 10,000 to 500,000 dinars, and a responsible person within a legal entity or authority faces 5,000 to 50,000 dinars for the same failures. Article 51 sets a lower ceiling for an important-system operator: a legal entity faces 50,000 to 1,000,000 dinars for the identical list of failures, a natural person faces 10,000 to 250,000 dinars, and a responsible person faces 5,000 to 50,000 dinars.

Rule
Fixed only
As of
18 September 2026
Minimum
50,000
Currency
RSD
Fixed cap
2,000,000

Who enforces it

Enforcement body

The ministry responsible for information security affairs, through its information-security inspectors, together with the Office for Information Security once established on 1 January 2027 (its functions are performed until then by the Office for Information Technologies and eGovernment, except the National CERT function, performed until then by the Regulatory Body for Electronic Communications and Postal Services); for a banking or financial-market operator, the National Bank of Serbia or the Securities Commission enforces under its own sectoral rules instead.

Settledness

As of
18 September 2026
Open questions
  • What general and sectoral criteria, including which size threshold, will the Government bylaw promised by Article 6 set for classifying an information-society-service provider or another Article 6 sector as an important ICT system, given the bylaw was not yet issued as of this reading and is due within 12 months of the law's entry into force?
  • Article 58 fixes the law's own entry into force at the eighth day after "Službeni glasnik Republike Srbije", br. 91/2025 was published, but that calendar date was not found in the primary text read for this document, so the effective_date recorded here instead rests on Article 55's own transitional deadline, the latest point at which the full Article 10-14 duty structure necessarily reaches every operator, including one still following the predecessor 2016 law's Articles 6a-11b until 31 December 2025: what calendar date did that gazette issue carry?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Articles 5 and 6 sort a duty-bearer into a priority or an important ICT system of special importance by sector, reaching an information-society service provider under Serbia's e-commerce law directly among the important-system sectors.

Articles 7 and 10 through 12 require every such operator to register, adopt and annually revise a risk-assessment act, adopt a security act built on it, check applied measures against that act at least once a year, and take thirty-seven itemised technical, operational, organisational and physical protection measures including multi-factor or continuous authentication.

A Government bylaw still to be issued will add general and sectoral criteria, including a size threshold, for designating an operator of either tier. A banking or financial-market operator instead follows sector-specific information-security rules the National Bank of Serbia or the Securities Commission issues under this law, which must provide at least the same level of effectiveness as Article 10's measures.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated statute text, Paragraf Lex (paragraf.rs), sourced from "Službeni glasnik Republike Srbije", br. 91/2025

Back to the example  ·  Lint your app