Why Critical Infrastructure in Bosnia and Herzegovina Isn't Mapped, and What That Actually Means
What a missed legislative deadline reveals about a country that cannot yet answer the most basic question in infrastructure protection: what needs protecting
Ask a security official in Sarajevo, Banja Luka, or Mostar to produce a list of the country's critical infrastructure, the power grid nodes, the water systems, the financial clearing platforms, the facilities whose failure would cascade into everything else, and the honest answer is that no such list exists at the state level. Not a classified one, not an outdated one, not one restricted to a handful of ministries. Bosnia and Herzegovina has no state law defining what counts as critical infrastructure and no inventory of the facilities that would fall under it, which means every conversation about protecting it is, definitionally, a conversation about protecting something nobody has agreed to name.
A Vacuum With a Deadline Attached
This is not a hypothetical gap. A working group under the Council of Ministers was formed in June 2025 specifically to draft a state-level law on the protection and resilience of critical entities, with a six-month deadline for producing that draft. The deadline passed in December 2025 without a text, and as of this year's reporting the process remains stalled. Sead Turčalo, dean of the Faculty of Political Sciences in Sarajevo, put the underlying problem plainly: without an inventory, what counts as critical infrastructure is a matter of guesswork, and everyone can reasonably assume the power grid or a defense-industry plant belongs on the list without anyone having the legal basis to say so with certainty. A country cannot build a response plan for the failure of something it has never formally defined.
Fragmentation Was Baked in Before the First Draft Was Written
What makes this gap harder to close than a simple drafting delay is the structure it has to close inside. Republika Srpska has already passed its own entity-level law on critical infrastructure security, complete with a risk-analysis methodology, security coordinators, and an inspection regime. The Federation of Bosnia and Herzegovina has no equivalent statute of its own. Brčko District sits outside both frameworks. A state-level law, when it eventually arrives, has to either absorb an entity law already in force or run in parallel with it, and either path runs directly into the same constitutional division of competences that slows nearly everything else in the country. Veldin Kadić of the Department for Peace and Security Studies in Sarajevo described the resulting condition precisely: the system formally exists on paper in places, but there is no single operational framework, so a serious incident, an attack on the energy grid, a cyberattack, a disruption to transport corridors, would meet a response that is slow, uncoordinated, and very likely insufficient.
No Inventory Means No Institution to Defend It
The absence of a critical infrastructure law compounds a second absence: Bosnia and Herzegovina still lacks a functioning state-level CERT and a cybersecurity strategy to go with it, along with the laws on information security and cybercrime jurisdiction that would normally accompany both. The reasons cited are less technical than political, insufficient political will to move the remaining draft laws forward, according to reporting on the stalled process. The consequence shows up in the numbers: Bosnia and Herzegovina ranks 82nd on the National Cyber Security Index, the lowest-ranked country in Europe on that measure, in the company of states with a fraction of its exposure to European critical systems. The next-lowest-ranked European country, Montenegro, sits at 51st, a gap that is not close.
Why "It's Probably the Grid and the Refineries" Isn't a Security Posture
There is a version of this problem that looks manageable from a distance: everyone with security experience already has a rough mental list of what BiH's critical infrastructure probably includes, the transmission network, water supply, the financial clearing system, telecommunications backbones, a handful of named public institutions. The difficulty is that a shared assumption is not a legal designation, and a legal designation is what triggers everything that follows it: mandatory risk assessments, security coordinators with actual authority, incident reporting obligations, inspection powers, and a chain of responsibility that activates automatically when something goes wrong rather than needing to be improvised in real time by whichever ministry picks up the phone first. Kadić's warning about the "gray zone" is exactly this: a system that formally exists without a unified framework behind it fails not because nobody cares, but because nobody has been assigned to care about a specific facility before the incident forces the question.
What the Region Around BiH Is Already Doing
The comparison that makes the gap sharper is not a distant one. Neighboring Serbia dealt with a threat to a gas pipeline in early 2026 that BiH's own analysts cited as a preview of a scenario the country is not currently equipped to answer. Croatia has a functioning state law on critical infrastructure with defined sectors, risk-analysis obligations, and a designated national contact point for EU coordination. Every country in the region moving toward EU accession is being asked to demonstrate exactly the kind of infrastructure mapping that BiH's own accession assessments have flagged as missing, alongside chronically underfunded and understaffed regulatory bodies for cybersecurity and digital governance. The absence is not just a domestic administrative gap. It is now a visible line item in the country's own accession risk assessments.
What Actually Needs to Happen First
None of this requires a novel policy idea; the RS law and the EU's own critical infrastructure directives already provide a template that a state-level law could adapt rather than invent from scratch. What it requires is finishing what was already started: a state-level definition of critical infrastructure, a sectoral inventory built from that definition, and an institution, whether a state CERT or a dedicated coordination body, with the authority to act on it across entity lines rather than within them. Until that inventory exists, every statement about protecting Bosnia and Herzegovina's critical infrastructure is describing an intention, not a system. The country is not failing to defend a known set of assets. It has not yet agreed on what the set is.
References:
Naslovna (2025, October 3). Zbog politike državni CERT tim u BiH i dalje na čekanju uprkos povećanim cyber prijetnjama.
Naslovna (2026, April 8). Probijen rok za donošenje nacrta zakona o kritičnoj infrastrukturi u BiH.
Fokus.ba (2025, September 23). Bosna i Hercegovina bi uskoro mogla dobiti zakon o zaštiti kritične infrastrukture.
Zakon o bezbjednosti kritičnih infrastruktura u Republici Srpskoj. BiH Pravo.
National Cyber Security Index, e-Governance Academy (Estonia).
[ Direct Line ]
Talk to Our Security Operations Team
If this briefing is relevant to your environment, our team can assess your exposure and show you how Outis defends critical infrastructure.




