Montenegro’s proposed Law on Critical Infrastructure Resilience would establish mandatory risk assessments, continuity planning and incident reporting for operators designated as critical, creating requirements across 11 sectors of the economy and public services. The sectors covered by the proposed legislation include transport, healthcare, drinking water, wastewater, digital infrastructure, public administration, and food production and distribution.
Companies and institutions classified as critical infrastructure operators would be required to establish resilience functions and prepare formal plans addressing prevention, protection, response and recovery. The framework would apply to risks extending beyond cybersecurity. Operators could require business-continuity planning, physical-security assessments, backup systems, supplier-risk reviews, emergency exercises, engineering assessments and employee training.
The proposed rules are based on maintaining essential services when infrastructure is disrupted by natural hazards, technical failures, sabotage or other incidents. For operators, resilience would therefore become part of the requirements associated with maintaining critical services rather than remaining solely a voluntary corporate practice. A water utility, hospital, food distributor or digital-infrastructure operator could be required to demonstrate that its primary assets are protected and that alternative suppliers, backup capacity and recovery procedures are available in the event of disruption.
This would create requirements for specialist engineering and advisory services combining operational, physical and digital risk assessments. The proposed legislation would also establish additional obligations for incident management. Critical operators would have to notify authorities of significant incidents within 24 hours and subsequently submit more detailed information. Corporate penalties for certain breaches could reach €20,000. The framework could also affect insurance arrangements by providing insurers with more information when assessing risks associated with critical assets. Documented resilience plans, stress testing and continuity measures would provide information on operational risks and the measures operators have established to manage them.
The scale of the market created by the legislation would depend on which companies and institutions are formally designated as critical infrastructure operators and on the implementing rules adopted under the framework. The resulting requirements would also involve recurring activities. Risk assessments would need to be updated, emergency plans tested, employees trained, and supplier networks and technical systems reviewed as they change. For designated operators, resilience requirements would therefore introduce an ongoing set of operational and compliance activities covering infrastructure protection, continuity and recovery.



