☰
ABOUT LES Blog
Services
Legal Services GDPR Compliance Strategic Project Proposals Policy & Research Consultancy HR Policy Advisory Cybersecurity Policy Advisory AI Policy & Regulatory Advisory
Publications
Law in Brief
Cyber Law
Cyber Law
AI Act
EU AI Act
Tools
Contract Review Assistant GDPR Compliance Policy Generator CyberLEX Global Privacy Audit Engine Compliance Handbook Compliance Comparator BizLaunch Tool
Contact

Strategic Analysis: Kosovo National Cyber Security Strategy 2023-2027

Deep Analysis: National Cyber Security Strategy of Kosovo (2023–2027) | LES & PARTNERS

National Cyber Security Strategy of Kosovo (2023–2027): Institutional Implementation under Law No. 08/L-173

Co-Authors: Pranvera, COO & Diona Zhubi, CEO/DPO at LES & Partners
Published: August 13, 2026
Strategic Legal & Regulatory Benchmark
Mandatory Executive Advisory Disclaimer This document presents an exhaustive legal, institutional, and technical analysis of the National Cyber Security Strategy 2023–2027 drafted under the leadership of the Ministry of Internal Affairs (MPB) of the Republic of Kosovo. It details statutory compliance obligations established under Law No. 08/L-173 on Cyber Security, the mandate of the Agency for Cyber Security (ASHK/KCSA), Critical Information Infrastructure (KII) oversight, and alignment with EU Directive 2022/2555 (NIS2).

1. Strategic Foundations & Institutional Framework

The Republic of Kosovo's National Cyber Security Strategy (2023–2027) sets the official roadmap for strengthening sovereign cyber defenses, protecting e-governance systems, and securing essential services across public and private sectors.

Coordinated by the MPB in collaboration with the national inter-institutional working group, the Strategy functions alongside Law No. 08/L-173 on Cyber Security (in force since March 2023). This statutory pairing establishes the operational mandate for the centralized Agency for Cyber Security (ASHK), which serves as the supreme regulator for national CSIRTs and operators of Critical Information Infrastructure (KII).

Statutory Enforcement Mandate Law No. 08/L-173 empowers ASHK to audit essential service providers, enforce technical standards, demand mandatory incident disclosures, and issue administrative fines for non-compliance.

Explore Strategy Objectives & Compliance Vectors

Evaluate the core strategic objectives of the 2023–2027 Strategy and inspect compliance obligations for enterprise and public institutions.

2. Deep Technical Breakdown: Strategic Objectives (2023–2027)

Strategic Objective I: Protection of Critical Information Infrastructure (KII)

Identification, Mandatory Baselines & EU NIS2 Alignment

Objective I focuses on establishing a resilient posture for national critical assets across energy, telecom, finance, water, transport, and public administration.

  • Identification Methodology: Establishes official criteria to identify and register Operators of Essential Services and Critical Information Infrastructure across Kosovo.
  • Mandatory Technical Baselines: Requires operators to adopt risk management frameworks aligned with international standards (ISO/IEC 27001, NIST) and EU NIS2 directives.
  • Supply Chain Audit Mandates: Obligates KII operators to conduct rigorous third-party risk assessments on all IT hardware, software, and external service providers.
Strategic Objective II: Building National Capacities & Threat Detection

National CERT Ecosystem, SOC Telemetry, and Incident Handling

Objective II lays out the technical and operational requirements to detect, respond to, and mitigate cyber incidents in real time.

  • ASHK & KSK-CERT Modernization: Upgrades the operational readiness of the national CSIRT/CERT ecosystem for rapid threat containment and cross-sector coordination.
  • Standardized Incident Reporting: Codifies formal escalation protocols and mandatory incident reporting SLAs for public and private KII entities.
  • Continuous Vulnerability Management: Requires periodic penetration testing, vulnerability scanning, and SIEM log monitoring across state networks.
Enterprise Compliance Directive (LES & Partners Advisory): Regulated entities must establish legally sound Incident Response Protocols. Law No. 08/L-173 requires prompt notification of significant cyber incidents to ASHK to ensure coordinated containment.
Strategic Objective III: Education, Capacity Building & Workforce Development

Addressing Human Capital & Professional Certification

Recognizing the global cyber skills gap, Objective III outlines state mechanisms to develop and retain specialized technical talent in Kosovo.

  • Academic & Vocational Integration: Coordinates with MESTI to embed specialized cybersecurity tracks within higher education and vocational training programs.
  • Public Sector Talent Retention: Introduces structural incentive programs and continuous professional training to retain cybersecurity talent within public administration.
  • Nationwide Awareness Campaigns: Executes targeted public hygiene initiatives to mitigate social engineering and phishing risks across businesses and citizens.
Strategic Objective IV: Legal Alignment & Standardisation

Harmonization with EU Acquis & International Norms

Objective IV focuses on ensuring Kosovo's regulatory landscape mirrors modern European standards.

  • NIS2 Directive Convergence: Phased updates to secondary legislation to achieve alignment with EU Directive 2022/2555 (NIS2).
  • Interoperability with Data Protection Laws: Harmonizes cybersecurity requirements with Kosovo's Law on Protection of Personal Data (GDPR convergence).

Approved Sovereign Incident Telemetry Protocol (ASHK Standard):

"[ASHK INCIDENT ESCALATION PROTOCOL] Unscheduled disruption or unauthorized access detected within Critical Information Infrastructure (KII). 1. Isolate compromised network segment immediately. 2. Transmit Incident Disclosure Form to ASHK / National CSIRT within required statutory window. 3. Preserve RAM dumps, SIEM logs, and firewall PCAP files for inspection under Law No. 08/L-173."
Strategic Objective V: International Cooperation & Cyber Diplomacy

NATO, ENISA, and Regional Partner Integration

Objective V emphasizes that state-level cyber defense requires strong bilateral and multilateral alliances.

  • NATO & EU Partnership: Deepening operational cooperation with NATO cyber defense mechanisms and EU cybersecurity initiatives.
  • Regional CERT Collaboration: Operational threat-sharing channels with regional CSIRTs across the Western Balkans.

3. Key Compliance Mandates under Law No. 08/L-173

To satisfy statutory requirements under Law No. 08/L-173 and the Strategy, enterprise leadership and legal teams must enforce:

  • βœ… **Designated Security Personnel:** Appoint a certified Information Security Officer (CISO) responsible for ASHK regulatory reporting.
  • βœ… **Annual Cyber Audits:** Conduct independent security audits aligned with ASHK guidelines.
  • βœ… **Mandatory Incident Disclosure:** Enforce internal SLAs to ensure timely reporting of cyber incidents to ASHK.
  • ❌ **Avoid Informal SLAs:** Ensure third-party IT vendors have strict, contractually binding security and patch management agreements.
LP
Authored by Pranvera (COO) & Diona Zhubi (CEO/DPO)

Executive Leadership at LES & Partners, specializing in corporate legal compliance, national cybersecurity governance, EU regulatory harmonization, and enterprise risk management.

CATEGORIES:

Tags:

Comments are closed

Solverwp- WordPress Theme and Plugin

LES & PARTNERS Footer