Cybersecurity in Serbia has entered a new regulatory phase. The new Information Security Act significantly changes how organizations must manage ICT risks, incidents, records, management accountability, and their approach to oversight.
If you follow the regulatory landscape in cybersecurity, you have certainly heard of the NIS2 Directive. Although Serbia is not a member of the European Union, the new law largely follows the logic of this directive: a broader scope of obligated entities, a stronger focus on risk assessment, mandatory incident reporting, stricter protection measures, and clearer management accountability.
The new regulatory framework directly affects executive management, legal and compliance teams, the risk function, the DPO, procurement, operations, and all organizations that rely on digital services or provide them to others.
Below, we highlight five changes that every organization should understand before an inspection, incident, client request, or tender raises the same question.
Priority or important ICT system — this is now much more than a formality
The new law divides ICT systems of special importance into two categories: priority and important ICT systems. The category an organization falls into directly affects the scope of obligations, level of oversight, protection measures, audit cadence, reporting obligations, and potential exposure to penalties.
- Priority ICT systems include sectors without which key state, economic, and social functions would be seriously jeopardized, such as energy, finance, healthcare, digital infrastructure, and certain ICT service providers.
- Important ICT systems include organizations whose disruption or compromise could have a significant economic or social impact, including certain manufacturing, logistics, food, utilities, and other sectors.
It is particularly important that the law also covers organizations that provide ICT services to others: hosting providers, data centres, cloud and software platforms, managed service providers, and other technology vendors. If you are part of the digital supply chain, the obligations may affect you directly or indirectly through your clients’ requirements.
Incorrect classification is not an administrative error. If an organization treats itself as less risky than it actually is, it may underestimate the scope of required measures, plan the budget incorrectly, miss deadlines, and enter regulatory oversight without adequate evidence of compliance.
Risk assessment becomes the foundation of every serious cybersecurity decision
Before NIS2 and the new domestic regulatory framework, many organizations had security documentation that was created once and then left in a drawer. The new law effectively abolishes that approach. Every operator of an ICT system of special importance is required to adopt a Risk Assessment Act and review it regularly. This is a logical requirement, because protection measures must match the current risk, not the situation from three years ago.
Risk assessment is the basis for all other security decisions: which controls to implement, how many resources to allocate, and how to prioritize remediation. A high-quality risk assessment gives management answers to three key questions: where we are most exposed, which measures have the greatest impact, and what we must demonstrate to the regulator, clients, or auditors.
For management, this is particularly important because the new cybersecurity approach requires a demonstrable link between risk, budget, protection measures, and accountability. In other words, it is not enough to say that the organization has an information security policy; it is necessary to show that measures were selected based on real risk and that their effectiveness is monitored.

An incident must not be “swept under the rug”
Under the new law, operators are required to report a security incident within 24 hours via a unified system operated by the competent national CERT. In NIS2 logic, early incident reporting is not just a formality; it is part of a broader system of coordination, damage reduction, and protection of users, the market, and the public interest.
Anyone who has had an incident or participated in its remediation knows that the first 24 hours are the most important. That is why organizations must have defined incident response procedures. At the moment of an incident, time must not be wasted agreeing on who does what, who informs management, who preserves evidence, who communicates with the regulator, and who makes the escalation decision.
In practice, an organization without a predefined incident response model can hardly meet the 24-hour deadline with sufficient quality.
If you do not have internal IR capacity, you can engage an external Incident Response team to help with procedures, preparation, tabletop exercises, and incident management if it has already occurred. This is particularly important for organizations that do not have a 24/7 SOC, a DFIR team, or a clearly defined crisis structure.
Records of ICT systems, IP addresses, and exposed services become a regulatory issue
One of the concrete novelties is the obligation to submit data on IP addresses as part of the ICT systems register. At first glance, this may seem like an administrative detail. In practice, the implications are operational and security-related.
To meet this obligation, you must know what you have. Many organizations do not have an up-to-date view of their own infrastructure, especially when it comes to cloud resources, hybrid environments, development environments, exposed services, and systems that have accumulated over the years without centralized visibility.
An IP address inventory is not just an Excel spreadsheet. It is a maturity test of asset management, cloud governance, vulnerability management, and attack surface management. If an organization does not know what it owns and what is exposed to the internet, it cannot claim it manages cyber risk.

This directly affects three areas:
Asset management – do you have an accurate and up-to-date inventory of all IP addresses, systems, services, and resource owners, including cloud and hybrid environments?
Attack surface management – do you know what is exposed externally, on which ports, with which technologies, and in what security state?
Vulnerability management – do you track vulnerabilities at the level of specific system resources, with clear owners, deadlines, and evidence of remediation?
Before the new law, organizations that were not in the regulator’s focus often postponed cleaning up records without direct consequences. Now, record-keeping becomes part of a legal obligation and one of the first elements that oversight can verify.
The Office for Information Security brings more centralized oversight and clearer coordination
The new law provides for the establishment of the Office for Information Security. It takes on a key coordination role in the information security system, including the functions of the national CERT, international cooperation, coordination, registers, training programs, etc.
For companies, this means a clearer point of contact with the state on cybersecurity matters, as well as a gradual shift from internal self-assessment to demonstrable oversight. Policies, procedures, and technical controls will have to be supported by evidence: minutes, logs, reports, risk assessments, training plans, test results, and records of implemented measures.
It is important to follow the development of this institution, because its capacity, working methodology, and approach to oversight will directly affect how organizations demonstrate compliance in practice.
Especially important: the law will also affect suppliers who may not formally be direct obligated entities
Even if your organization is not formally an operator of a priority or important ICT system, the new regulatory framework will likely affect you through client requirements. Banks, insurance companies, the public sector, healthcare institutions, energy companies, and large enterprises will increasingly require proof that their suppliers have adequate cybersecurity measures, incident response capacity, vulnerability management, access control, and basic regulatory documentation.
Where should you start?
The first step is not buying a new tool. The first step is understanding the obligations, classification, risks, and current maturity level.
Concrete steps to take:
- Determine your classification – are you a priority ICT system, an important ICT system, or a supplier that will be indirectly affected by your clients’ requirements?
- Initiate a Risk Assessment – without it, you have no basis for any next step.
- Review Incident Response procedures – do you have the capacity to respond, document, and report an incident within 24 hours?
- Update your infrastructure inventory – especially IP addresses, exposed services, cloud resources, and critical systems.
- Educate management and employees – cybersecurity is now an organizational responsibility, not just a technical issue.
- Prepare evidence – policies, procedures, logs, minutes, test results, and records of implemented measures.
How can we help?
PULSEC helps organizations translate the new Information Security Act and NIS2 requirements into a concrete, demonstrable, and feasible compliance program. Our approach connects regulatory interpretation, GRC methodology, technical validation, and operational cyber defense.
- organization classification and an initial NIS2 / Information Security Act Gap Assessment;
- drafting the Risk Assessment Act and prioritizing protection measures;
- establishing incident response procedures and a 24-hour reporting model;
- vCISO support for management, IT, risk, and compliance teams;
- vulnerability assessment, penetration testing, and attack surface assessment;
- awareness training for employees and management;
- preparing documentation, records, and evidence materials for oversight;
- support through SOC, Incident Response, and DFIR capabilities.
If you are not sure where to start, begin with one question: can you prove today that you know your risks, your obligations, and your critical systems?
If the answer is “no” or “we are not sure,” now is the right time to speak with our team.