Cybersecurity governance in the western Balkans: NIS2 alignment, institutional capacity and critical infrastructure protection
Abstract
This paper aims to examine cybersecurity governance in the Western Balkans through the combined lens of NIS2 alignment, institutional capacity and critical infrastructure protection. It treats cybersecurity as a regulatory and governance problem rather than as a purely technical domain. The study adopts a comparative exploratory regulatory case-study design covering Albania, Bosnia and Herzegovina, Kosovo, Montenegro, North Macedonia and Serbia. The empirical basis is a document corpus composed of cybersecurity laws, national strategies, CSIRT/CERT institutional sources, critical infrastructure documents, EU enlargement reports, NIS2-related material and regional policy evidence. The framework identifies a structured basis for comparing formal legal alignment with operational governance capacity. The most relevant differences concern institutional fragmentation, competent-authority design, incident-reporting arrangements, CSIRT/CERT maturity and the integration of cybersecurity into critical infrastructure protection. The paper provides a policy-relevant framework for accession-oriented cybersecurity reforms, especially where legal transposition must be connected to enforcement, coordination and cross-border resilience. The paper develops a comparative regulatory framework for analysing NIS2-aligned cybersecurity governance capacity in the Western Balkans as a regional governance challenge.