- Home
Cyber Security Agency of Montenegro Cybersecurity Agency Launches First Information Se...
Cybersecurity Agency Launches First Information Security Supervision Cycle

As announced, the Cybersecurity Agency launched the first cycle of supervision of the implementation of information security measures in July.
The Agency sent an initial questionnaire to public authorities and other entities designated as essential and important entities under the Law on Information Security. The aim was to gain an insight into the current level of implementation of information security measures based on the responses received, and to assess the state of cybersecurity across the sectors defined by the law.
Among other things, the purpose of the first supervisory cycle is to gain insight into how entities manage information security, the level of management involvement in cybersecurity risk management, and their understanding of legal obligations, while also establishing cooperation between the Agency and the supervised entities.
An analysis of the responses received so far indicates that essential entities exhibit higher compliance with information security measures than important entities, while certain sectors show high compliance.
The responses also indicate that some of the most significant weaknesses relate to the organisation of information security and the allocation of responsibilities, as well as employee management and awareness-raising. This points to the need for more active management involvement in implementing information security measures within the entities they lead.
However, these findings are based on the self-assessments of entities that have submitted their responses to date. The Agency will deliver the final assessment of compliance following comprehensive supervisory activities planned for the next phase.
Supervision has already been conducted at one essential entity, while further supervisory activities involving entities from several sectors are planned by the end of 2026. The supervision will assess whether entities are implementing information security measures relating to the protection of data and network and information systems, as well as risk management in this area.
It is important to highlight that the Agency’s activities focus on critical infrastructure - specifically, essential and important entities that rely on information and communication technologies and deliver services vital to the lives, health, and safety of citizens, as well as to the functioning of the state. On the other hand, supervision of the implementation of information security measures within public administration bodies is carried out by the Ministry of Public Administration.
The Agency plans to organise, in cooperation with national and international partners, working meetings and training sessions for essential and important entities, to provide support and further strengthen their capacities to implement information security measures.
By carrying out these activities and rigorously enforcing regulations within its mandate, the Agency will help build a secure and resilient digital environment in Montenegro

