National Cyber Security Strategy of Kosovo (2023β2027): Institutional Implementation under Law No. 08/L-173
Co-Authors: Pranvera, COO & Diona Zhubi, CEO/DPO at LES & Partners
Published: August 13, 2026
Strategic Legal & Regulatory Benchmark
1. Strategic Foundations & Institutional Framework
The Republic of Kosovo's National Cyber Security Strategy (2023β2027) sets the official roadmap for strengthening sovereign cyber defenses, protecting e-governance systems, and securing essential services across public and private sectors.
Coordinated by the MPB in collaboration with the national inter-institutional working group, the Strategy functions alongside Law No. 08/L-173 on Cyber Security (in force since March 2023). This statutory pairing establishes the operational mandate for the centralized Agency for Cyber Security (ASHK), which serves as the supreme regulator for national CSIRTs and operators of Critical Information Infrastructure (KII).
Explore Strategy Objectives & Compliance Vectors
Evaluate the core strategic objectives of the 2023β2027 Strategy and inspect compliance obligations for enterprise and public institutions.
2. Deep Technical Breakdown: Strategic Objectives (2023β2027)
Identification, Mandatory Baselines & EU NIS2 Alignment
Objective I focuses on establishing a resilient posture for national critical assets across energy, telecom, finance, water, transport, and public administration.
- Identification Methodology: Establishes official criteria to identify and register Operators of Essential Services and Critical Information Infrastructure across Kosovo.
- Mandatory Technical Baselines: Requires operators to adopt risk management frameworks aligned with international standards (ISO/IEC 27001, NIST) and EU NIS2 directives.
- Supply Chain Audit Mandates: Obligates KII operators to conduct rigorous third-party risk assessments on all IT hardware, software, and external service providers.
National CERT Ecosystem, SOC Telemetry, and Incident Handling
Objective II lays out the technical and operational requirements to detect, respond to, and mitigate cyber incidents in real time.
- ASHK & KSK-CERT Modernization: Upgrades the operational readiness of the national CSIRT/CERT ecosystem for rapid threat containment and cross-sector coordination.
- Standardized Incident Reporting: Codifies formal escalation protocols and mandatory incident reporting SLAs for public and private KII entities.
- Continuous Vulnerability Management: Requires periodic penetration testing, vulnerability scanning, and SIEM log monitoring across state networks.
Addressing Human Capital & Professional Certification
Recognizing the global cyber skills gap, Objective III outlines state mechanisms to develop and retain specialized technical talent in Kosovo.
- Academic & Vocational Integration: Coordinates with MESTI to embed specialized cybersecurity tracks within higher education and vocational training programs.
- Public Sector Talent Retention: Introduces structural incentive programs and continuous professional training to retain cybersecurity talent within public administration.
- Nationwide Awareness Campaigns: Executes targeted public hygiene initiatives to mitigate social engineering and phishing risks across businesses and citizens.
Harmonization with EU Acquis & International Norms
Objective IV focuses on ensuring Kosovo's regulatory landscape mirrors modern European standards.
- NIS2 Directive Convergence: Phased updates to secondary legislation to achieve alignment with EU Directive 2022/2555 (NIS2).
- Interoperability with Data Protection Laws: Harmonizes cybersecurity requirements with Kosovo's Law on Protection of Personal Data (GDPR convergence).
Approved Sovereign Incident Telemetry Protocol (ASHK Standard):
NATO, ENISA, and Regional Partner Integration
Objective V emphasizes that state-level cyber defense requires strong bilateral and multilateral alliances.
- NATO & EU Partnership: Deepening operational cooperation with NATO cyber defense mechanisms and EU cybersecurity initiatives.
- Regional CERT Collaboration: Operational threat-sharing channels with regional CSIRTs across the Western Balkans.
3. Key Compliance Mandates under Law No. 08/L-173
To satisfy statutory requirements under Law No. 08/L-173 and the Strategy, enterprise leadership and legal teams must enforce:
- β **Designated Security Personnel:** Appoint a certified Information Security Officer (CISO) responsible for ASHK regulatory reporting.
- β **Annual Cyber Audits:** Conduct independent security audits aligned with ASHK guidelines.
- β **Mandatory Incident Disclosure:** Enforce internal SLAs to ensure timely reporting of cyber incidents to ASHK.
- β **Avoid Informal SLAs:** Ensure third-party IT vendors have strict, contractually binding security and patch management agreements.
Authored by Pranvera (COO) & Diona Zhubi (CEO/DPO)
Executive Leadership at LES & Partners, specializing in corporate legal compliance, national cybersecurity governance, EU regulatory harmonization, and enterprise risk management.
National Strategy Objective Evaluator
Select a Strategic Objective to review its core focus and compliance requirements:
