NEWS
High-speed train with EU flag on the front at a Brussels station, passengers waiting on the platform beneath a curved glass roof.

Information Technology and Serbian Train to EU

On its way to harmonise information security regulations with NIS 2 Directive and make an adequate response to rapidly changing cybersecurity environment, the Serbian Parliament rendered new Law on Information Security (the New Law) in December 2025. At this moment, an ongoing public debate is aimed to adoption of bylaws to implement the New Law.

By careful reading of provisions of the New Law governing scope of its application, we understand the lawmaker created a confusion about elementary questions:

a) Unlike the NIS 2 Directive, the New Law does not establish size-cap criteria for determining whether it is applicable to an entity and whether an entity should be classified as essential or important. The New Law does authorise the Government to regulate such criteria by secondary legislation, which can create confusion dur to the absence of statutory basis for such differentiation.

b) It remains unclear which regulatory regime applies to tax authorities, public prosecutor’s offices, and courts. Specifically, it is uncertain whether these authorities are to be treated as independent ICT operators, and therefore partially exempt from the New Law, or whether they fall within the category of essential entities and are fully subject to its provisions.

c) With respect to trust services provided by an independent ICT operator (the Ministry of Interior), it is unclear whether the applicable regime is that governing independent ICT operators or the regime applicable to essential entities.

This Article by Nikola Djordjević and Ivan Milošević, partners in JPM Belgrade office,  is aimed to open a debate for clarification of ambiguities in the New Law.

author avatar
JPM Law Office
Scroll to Top

Privacy Policy

Law firm Janković, Popović & Mitić Beograd takes care of your privacy. As a controller and in accordance with the Law on Personal Data Protection and other applicable personal data protection regulations, we are obliged to provide you with information related to processing of your personal data.

We use cookies to help improve your experience of our website by measuring how it’s used.

Read our Privacy & Cookie policy for more information.

This Privacy Notice describes which personal data we collect from you and in which manner, how we use and share your personal data. It contains information on purposes and legal grounds for processing, on the time period in which we store your personal data, the manner we protect this data as well as on your rights.