Cybersecurity within Kosovo’s Legal Framework
Digitalization has changed the way organizations deliver services, manage information, and communicate with customers, partners, and public institutions. At the same time, dependence on network and information systems has increased exposure to cybersecurity incidents.
In this context, the Republic of Kosovo has established a dedicated legal framework for cybersecurity through Law No. 08/L-173 on Cybersecurity, published in the Official Gazette of the Republic of Kosovo on 27 February 2023.
The Law defines cybersecurity principles, the institutions responsible for developing, implementing, and promoting cybersecurity policy, the responsibilities of relevant authorities, the duties of cybersecurity entities, inter-institutional cooperation, the prevention of cyberattacks, and establishes the Cybersecurity Agency (CSA).
The Law partially transposes Directive (EU) 2013/40 on attacks against information systems and Directive (EU) 2016/1148 concerning measures for a high common level of security of network and information systems (NIS Directive).
What Does Law No. 08/L-173 Regulate?
The Law establishes the legal basis for organizing and ensuring cybersecurity in the Republic of Kosovo.
Among the main matters regulated by the Law are:
- principles for ensuring cybersecurity;
- security measures for Operators of Essential Services;
- obligations for notifying cybersecurity incidents;
- security measures for Digital Service Providers;
- prevention and resolution of cybersecurity incidents;
- institutional organization of cybersecurity;
- competencies of the Cybersecurity Agency;
- interinstitutional cooperation;
- supervision and enforcement of legal requirements.
The Law should be read together with the secondary legislation adopted pursuant to it. The Official Gazette lists, among others, secondary legislation concerning incident notification, the incident register, the register of cybersecurity risks and threats, response measures, and institutional organization.
Principles for Ensuring Cybersecurity
The Law establishes four main principles:
Principle of Responsibility
The security of a system is organized by the service provider.
Principle of Comprehensive Protection
The service provider must identify potential risks affecting the network and information system and implement appropriate organizational and technical measures for its protection.
Principle of Minimizing Adverse Effects
In the event of a cybersecurity incident, the service provider must exercise due care and implement the necessary measures to prevent the possible escalation and spread of the incident and notify the supervisory authority in accordance with the Law.
Principle of Cooperation
The parties must cooperate in ensuring cybersecurity and resolving incidents, taking into account, where necessary, the interconnection and dependencies between systems and services.
Does Law No. 08/L-173 Apply Equally to Every Organization?
No.
The Law establishes specific obligations for certain categories of entities, particularly:
- Operators of Essential Services (OES);
- Digital Service Providers (DSP);
- other institutions and mechanisms defined by the Law.
Therefore, an organization should not automatically assume that all obligations under Law No. 08/L-173 apply to it in the same manner.
Before establishing a compliance program, the organization should determine its legal status and identify the specific obligations applicable to it.
What Does the Law Require from Operators of Essential Services?
Article 5 of the Law establishes specific requirements concerning security measures for the systems of Operators of Essential Services.
An OES must continuously implement security measures that are:
- organizational;
- physical;
- information technology-related.
These measures must aim to:
- prevent cybersecurity incidents;
- resolve cybersecurity incidents;
- prevent and mitigate impacts on service continuity or system security;
- prevent and mitigate potential impacts on the continuity of another dependent service or the security of another system.
Risk Assessment
One of the specific obligations of an OES is to prepare a system risk assessment.
According to the Law, the assessment must, among other things, contain a list of risks affecting system security and service continuity that may cause cybersecurity incidents.
The severity of the consequences of an incident must also be determined, taking into account the parameters established by the Law, including:
- the number of users affected by the disruption of the essential service;
- the duration of the incident;
- the geographical extent of the affected area.
The OES must also describe measures for resolving the cybersecurity incident.
From an implementation perspective, these requirements may be supported by a documented risk assessment methodology and documentation enabling the identification, assessment, treatment, and monitoring of risks.
Documentation and Monitoring
The Law requires an OES to ensure the existence of documentation concerning:
- the system risk assessment;
- security regulations;
- a description of the security measures to be implemented.
The OES must also ensure system monitoring to detect actions or software that compromise its security and provide the CSA with information concerning actions or software that compromise system security.
In the event of an incident, measures must be taken to reduce its impact and spread, including, where necessary, restricting the use of or access to the system.
Review of Security Measures
An OES must review:
- the adequacy;
- the effectiveness;
- compliance of implementation
of the security measures and document the results.
Documents relating to these results must be retained for at least three (3) years from the date of their creation.
This is a specific requirement of the Law and not merely a recommended practice.
CSIRT or Officer Responsible for Security
The Law establishes that an Operator of Essential Services is required:
to establish an OES CSIRT or, at a minimum, appoint an officer responsible for the security of network and information systems.
An OES may participate in a national sectoral CSIRT, but such participation does not release it from this obligation.
Responsibility for security must therefore be clearly defined within the organizational structure.
Responsibility for Systems Managed or Hosted by Third Parties
A particularly important requirement of the Law concerns outsourcing and hosting.
Where an OES authorizes another party to administer its system or uses another party to host the system, the OES remains responsible for the implementation of the system security measures by that third party.
This means that transferring technical operations to an external provider does not eliminate the OES’s responsibility under the Law.
From a practical perspective, this requires adequate oversight of third-party relationships and verification of the security measures implemented by those parties.
Incident Reporting by OES
Article 6 establishes the obligation of Operators of Essential Services to notify cybersecurity incidents.
An OES must inform the Cybersecurity Agency immediately, but no later than twenty-four (24) hours after becoming aware of the incident, where the incident:
- has a significant impact on system security or service continuity; or
- the significant impact is not clear but may reasonably be assumed.
The Law also establishes criteria for assessing whether an impact is significant.
The reporting procedure and content have been further specified through Administrative Instruction (MIA) No. 03/2024 on the Procedure for Notification and the Content of the Cybersecurity Incident Report, published on 27 August 2024.
What Should an OES Be Able to Do During an Incident?
The legal requirements imply that an OES should be able to:
- identify the incident;
- assess its impact;
- determine whether the notification criteria are met;
- activate internal response mechanisms;
- take measures to reduce the impact and spread of the incident;
- notify the CSA where the legal conditions are met;
- document the actions and measures taken.
A documented and tested incident management procedure is a practical way to support compliance with these requirements.
What Does the Law Require from Digital Service Providers?
The Law separately establishes obligations for Digital Service Providers (DSPs).
Under Article 7, a DSP must:
- identify risks affecting the security of its systems;
- analyze those risks;
- implement appropriate organizational and technical measures for risk management.
When selecting security measures, consideration must be given to:
- security of the technical infrastructure;
- prevention, detection, and resolution of cybersecurity incidents;
- business continuity management;
- monitoring, auditing, and testing;
- compliance with international standards.
A DSP must also implement appropriate measures to minimize the impact of incidents on service continuity.
CSIRT or Responsible Security Officer for DSPs
A Digital Service Provider is also required:
to establish a DSP CSIRT or, at a minimum, appoint an officer responsible for the security of network and information systems.
Participation in a national sectoral CSIRT does not eliminate this obligation.
Incident Reporting by DSPs
The incident reporting requirements for DSPs should not be confused with the 24-hour deadline established for OESs.
Under Article 8, a DSP must notify the CSA of a cybersecurity incident that has a significant impact on the digital service provided, immediately after becoming aware of the incident.
When determining whether an impact is significant, consideration is given to:
- the number of users affected;
- the duration of the incident;
- the geographical extent;
- the extent of disruption to the functioning of the service;
- the impact on economic and societal activities.
The Law also contains additional provisions concerning the content and destination of notifications, cross-border impacts, and situations where an OES relies on a DSP as a third party.
Registers of Incidents, Risks, and Threats
The legal and secondary regulatory framework also includes mechanisms for registering cybersecurity incidents, risks, and threats.
In particular, the following have been adopted:
- Administrative Instruction (MIA) 04/2024 on the Register of Cybersecurity Incidents;
- Administrative Instruction (MIA) No. 05/2024 on the Register of Cybersecurity Risks and Threats.
These acts must be interpreted according to their specific scope and obligations. The existence of state registers should not automatically be presented as an obligation for every organization to establish its own register in a particular format or under a specific title, unless such an obligation derives from the requirements applicable to that entity.
Nevertheless, documenting risks and incidents is a practical mechanism for demonstrating and managing the implementation of security measures.
Technical Measures Are Not Defined as Specific Products
The Law establishes security measures and outcomes, but it should not be interpreted as necessarily requiring specific technology products.
For example, Law No. 08/L-173 does not establish a universal requirement to use a specific:
- SIEM;
- EDR/XDR;
- firewall;
- IAM;
- PAM;
- vulnerability management platform;
- backup technology.
Such technologies may be used as practical means of implementing the required measures, depending on the risks, systems, services, and specific requirements applicable to the organization.
It should nevertheless be emphasized that, for OESs, the Law expressly requires, among other things, system monitoring to detect actions or software that compromise system security.
How Much Documentation Should an Organization Maintain?
Compliance should not be equated with producing a large number of policies.
For OESs, the Law specifically requires the existence of documentation concerning the system risk assessment, security regulations, and the description of security measures.
It also requires documentation of the results of reviews of the adequacy, effectiveness, and compliance of the implementation of security measures, with such records retained for at least three years from their creation.
Practical Supporting Documentation
Depending on the status and needs of the organization, the security program may be supported by, among other things:
- Information Security Policy;
- Cybersecurity Policy;
- asset inventory or asset register;
- risk assessment methodology;
- risk assessment documentation;
- risk treatment plan;
- incident management procedure;
- vulnerability management procedure;
- patch management procedure;
- backup and recovery procedures;
- service continuity documentation;
- access control procedures;
- third-party management documentation;
- monitoring documentation;
- security audit and testing reports;
- evidence of controls and corrective measures.
This list should not be interpreted as a list of documents that Law No. 08/L-173 expressly requires under these specific titles.
It represents a practical structure for organizing and demonstrating the implementation of security measures.
Suppliers, Outsourcing, and Hosting
For OESs, the Law is clear: where the operator authorizes another party to administer its system or uses another party to host the system, the operator remains responsible for the implementation of system security measures by that third party.
Therefore, the use of outsourcing, hosting, or other external services should not be considered an automatic transfer of legal responsibility.
As a risk management practice, relationships with suppliers may address:
- security requirements;
- access control;
- incident management and notification;
- continuity;
- recovery;
- subcontracting;
- monitoring and auditing;
- handling of information and data.
These elements should be adapted to the specific relationship and applicable legal or contractual requirements.
Service Continuity and Recovery
Continuity is an important component of the Law’s requirements.
For OESs, security measures must address the prevention and mitigation of the impact of an incident on service continuity.
For DSPs, the Law requires that business continuity management be considered when selecting security measures and that appropriate measures be taken to minimize the impact of incidents on service continuity.
In practice, these requirements may be supported by:
- business continuity plans;
- recovery plans;
- system recovery procedures;
- backup and restore mechanisms;
- service restoration priorities;
- defined roles and responsibilities;
- exercises and testing.
The Law should not be interpreted as automatically requiring every organization to maintain documents specifically titled Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP). These are practical mechanisms for addressing continuity and recovery requirements.
ISO 27001, NIST, NIS2, and DORA: Requirement or Practice?
ISO/IEC 27001
ISO/IEC 27001 may be used to establish an Information Security Management System.
However:
ISO/IEC 27001 certification is not established by Law No. 08/L-173 as a universal requirement for organizations.
ISO/IEC 27001 can help structure risk management, policies, responsibilities, controls, auditing, and continual improvement.
For DSPs, the Law expressly provides that, when selecting measures to ensure security, compliance with international standards must also be taken into account. This provision is not equivalent to a requirement for ISO/IEC 27001 certification.
NIST Cybersecurity Framework
The NIST Cybersecurity Framework may be used as a practical framework for structuring cybersecurity risk management.
It does not replace the requirements of Law No. 08/L-173 and should not be presented as a mandatory standard under this Law.
NIS2
Law No. 08/L-173 partially transposes the 2016 NIS Directive — Directive (EU) 2016/1148, not the NIS2 Directive.
Therefore, NIS2 should not be presented as an obligation arising automatically from Law No. 08/L-173.
NIS2 may be used as a reference for the further development of cybersecurity practices and may be relevant for certain organizations due to their activities or business relationships with the European Union market.
DORA
DORA is a European Union regulation concerning digital operational resilience in the financial sector.
DORA is not an obligation arising from Law No. 08/L-173.
The applicability of DORA to a particular organization must be assessed separately.
What Should an Organization Do?
1. Determine Legal Status
Determine whether the organization is an OES, DSP, or another entity subject to specific requirements under the Law.
2. Identify Specific Requirements
Do not begin with a generic cybersecurity checklist. Identify the specific provisions of the Law and secondary legislation that apply to the organization.
3. Perform the Risk Assessment
For entities subject to this requirement, prepare the risk assessment in accordance with the parameters defined by the Law and relevant secondary legislation.
4. Implement Security Measures
Implement the organizational, physical, and/or technical measures required according to the organization’s category.
5. Define Responsibility
For OESs and DSPs, ensure the establishment of the relevant CSIRT or, at a minimum, appoint an officer responsible for the security of network and information systems.
6. Prepare for Incident Management
Ensure the capability to identify, assess, respond to, document, and notify incidents in accordance with the applicable requirements.
7. Review Effectiveness
For OESs, review the adequacy, effectiveness, and compliance of the implementation of security measures and document the results.
8. Manage Third Parties
Where systems are administered or hosted by third parties, ensure that the required security measures are also implemented by those parties.
9. Retain Evidence
Retain documentation in accordance with the applicable legal requirements and retention periods.
Compliance Is Not Simply a Checklist
An organization cannot automatically be considered compliant merely because it has:
- a firewall;
- antivirus;
- EDR;
- backups;
- SIEM;
- a security policy;
- or ISO certification.
Compliance must be assessed against the specific legal obligations applicable to the entity.
For OESs, the Law requires not only the existence of security measures but also the review of their adequacy, effectiveness, and compliance of implementation, as well as documentation of the results.
This makes implementation evidence an important component of demonstrating compliance.
Conclusion
Law No. 08/L-173 on Cybersecurity has established the legal framework for ensuring cybersecurity in the Republic of Kosovo and has established the Cybersecurity Agency.
For Operators of Essential Services and Digital Service Providers, the Law establishes specific obligations concerning risk management, security measures, organizational responsibilities, and the management and notification of cybersecurity incidents.
In particular, OESs are required to maintain continuous organizational, physical, and information technology security measures, perform risk assessments, maintain documentation, conduct monitoring, review the effectiveness of security measures, retain evidence, remain responsible for systems administered or hosted by third parties, and establish a CSIRT or appoint a responsible security officer.
DSPs are required to identify and analyze risks, implement appropriate organizational and technical measures, consider infrastructure security, incident management, continuity, monitoring, auditing, testing, and international standards, and establish a CSIRT or appoint a responsible security officer.
Organizations should clearly distinguish between:
Legal obligation – what is expressly required by Law No. 08/L-173 and applicable secondary legislation;
Practical implementation measure – the method chosen by the organization to meet a legal requirement;
Good practice – additional measures that help strengthen security and improve risk management;
External standard or framework – such as ISO/IEC 27001, ISO/IEC 27002, or the NIST Cybersecurity Framework, which may help structure a security program but should not be presented as universal obligations under Law No. 08/L-173.
FAQ – Frequently Asked Questions
Does every company in Kosovo have to comply with the same obligations under Law No. 08/L-173?
No. The status of the entity must be determined, together with the specific requirements of the Law and secondary legislation that apply to it.
Is ISO/IEC 27001 mandatory under the Law?
Not as a universal requirement. The Law does not establish ISO/IEC 27001 certification as a universal obligation.
For DSPs, however, the Law requires that compliance with international standards be taken into account when selecting security measures.
How quickly must an OES report an incident?
Where the conditions of Article 6 are met, an OES must notify the CSA immediately, but no later than 24 hours after becoming aware of the cybersecurity incident.
Is the 24-hour deadline the same for DSPs?
No. Article 8 provides that a DSP must notify the CSA of an incident having a significant impact on the digital service immediately after becoming aware of the incident. The specific 24-hour deadline under Article 6 applies to OESs.
Must an OES have a CSIRT?
The Law requires the establishment of an OES CSIRT or, at a minimum, the appointment of an officer responsible for the security of network and information systems.
Does the same requirement apply to DSPs?
Yes. A DSP must establish a DSP CSIRT or, at a minimum, appoint an officer responsible for the security of network and information systems.
Is responsibility transferred if the OES system is hosted by another company?
No. The Law provides that where an OES authorizes another party to administer its system or uses another party to host the system, the OES remains responsible for the implementation of system security measures by that third party.
Does the Law require documents specifically called BCP and DRP?
Not as universal documents under those titles. However, service continuity forms part of the legal requirements applicable to relevant entities, and BCP and DRP may be used as practical mechanisms for addressing those requirements.
Does NIS2 automatically apply in Kosovo through this Law?
No. Law No. 08/L-173 partially transposes the 2016 NIS Directive. NIS2 should not be presented as an obligation automatically arising from Law No. 08/L-173.
What is the first step for an organization?
The first step is to determine the organization’s legal status and the scope of the applicable obligations. Only after this should a gap assessment be performed and the necessary measures identified.
Legal References
This article is based on Law No. 08/L-173 on Cybersecurity, published in Official Gazette No. 4/2023 on 27 February 2023, together with the secondary legislation adopted pursuant to it.
Relevant secondary legislation includes:
- Administrative Instruction (MIA) No. 03/2024 on the Procedure for Notification and the Content of the Cybersecurity Incident Report;
- Administrative Instruction (MIA) 04/2024 on the Register of Cybersecurity Incidents;
- Administrative Instruction (MIA) No. 05/2024 on the Register of Cybersecurity Risks and Threats;
- Administrative Instruction (MIA) No. 08/2024 on Measures and Procedures Restricting or Temporarily Suspending the Use of or Access to Network or Information Systems in the Event of a Cybersecurity Incident.
Primary source: Official Gazette of the Republic of Kosovo – Law No. 08/L-173 on Cybersecurity.Note: This article is for informational purposes only and does not constitute a legal opinion regarding any specific entity. The applicability of obligations should be determined on a case-by-case basis, taking into account the status of the entity and the legislation in force.