A shift from voluntary cybersecurity to regulated cybersecurity
A shift from voluntary cybersecurity to regulated cybersecurity
Network and Information Security Directive - NIS2 is an updated EU framework for cybersecurity of critical infrastructure and essential services. It is, along with DORA and GDPR, one of the most essential pieces of legislation shaping the EU's approach to security in cyberspace.
As an EU Candidate country, Bosnia and Herzegovina is expected to gradually align its legislation with the EU acquis in cybersecurity and personal data protection. Alignment with NIS2 would signal significant progress in Chapter 10 (Information Society & Media) and Chapter 24 (Justice, Freedom & Security) of the accession process.
So, what does this mean for Bosnia and Herzegovina?
Compliance with NIS2 would require major legal and institutional reform. It starts with the mandate for a National Authority to implement, oversee, and enforce NIS2-compliant legislation. This would naturally fall to the Ministry of Security of BiH, which currently lacks the legal mandate to do so. Compounding this, the Ministry has been without a Minister since the former Minister resigned in January 2025, and the Council of Ministers has yet to nominate a replacement. Without a Minister, the Ministry cannot place legislation into parliamentary procedure.
NIS2 also requires Bosnia and Herzegovina to adopt a National Cybersecurity Strategy. In most countries, this would be a significant undertaking. In BiH, it is made considerably harder by the country's complex governance structure. With no political consensus at the state level, the process remains blocked - though the entities are pressing ahead with their own sub-national strategies in the meantime. While this is an advancement on the overall scene of cybersecurity, it signals a fragmented approach that does not satisfy the NIS2 requirements and does not reflect well on BiH’s trajectory towards EU accession.
The sectoral picture compounds this further. Most of the sectors covered by NIS2 are regulated at the entity level, not the state level. Meaningful alignment would require coordinated legislative action across the Federation of BiH, Republika Srpska, and Brčko District - a level of inter-institutional cooperation that has, so far, proven difficult to sustain. In addition, RS has recently sparked concerns across the country and the international community, especially the EU, after awarding a tender for critical infrastructure cybersecurity equipment to a company based in the Peoples Republic of China. It is worth noting that BiH has recently been identified as one of the countries with suspected or confirmed UNC2814 (“Gallium”) victims, a cyber-intelligence group linked to PRC, that has exploited backdoor access to obtain sensitive personal information from the telecommunications sector.
What is the path forward?
The direction is not in question. EU accession is a stated strategic priority for Bosnia and Herzegovina, and cybersecurity alignment is part of the package. The question is whether the political conditions can be created to act on it.
The immediate steps are clear: appoint a Minister of Security, initiate a state-level cybersecurity law establishing a national authority and CERT mandate, and open a structured dialogue between state and entity governments on how NIS2 obligations are divided. While international bodies can offer technical and financial support, the decisions to act upon this must be made here and now.
Bosnia and Herzegovina recorded an estimated 27 million cyber incidents in January 2026 alone. State-sponsored actors have already identified the country as a target. Critical infrastructure operates without the legal frameworks that NIS2 would require. The window for an orderly, structured alignment is narrowing - and the alternative is not a slower accession process, but unprotected systems in an increasingly hostile threat environment.
The wheels of legislation need to move. Mandates must be urgently expanded. The appointment of a new minister must also be treated as a practical matter for security, not just a political one. And while policymakers work to close the institutional gap, the organizations that operate critical infrastructure in Bosnia and Herzegovina cannot afford to wait for a law to tell them to act. With attackers working at unprecedented speed, the country needs to move towards advanced cybersecurity - every day lost brings attackers a step closer to our critical infrastructure.
The threat is already here. So is the expertise to address it.
[ Direct Line ]
Talk to Our Security Operations Team
If this briefing is relevant to your environment, our team can assess your exposure and show you how Outis defends critical infrastructure.




