Montenegro’s forthcoming legislation on critical infrastructure is poised to establish a significant market for risk consulting, resilience engineering, and security services. This initiative mandates essential operators to conduct risk assessments, formulate continuity plans, and engage in incident reporting.
The proposed Law on Critical Infrastructure Resilience encompasses 11 sectors, which include transport, healthcare, drinking water, wastewater management, digital infrastructure, public administration, as well as food production and distribution.
Entities categorized as critical will be required to implement resilience functions, evaluate risks, and develop formal strategies that address prevention, protection, response, and recovery protocols.
The implications of this law extend beyond mere cybersecurity concerns.
Operators may find it necessary to pursue business-continuity planning, physical-security audits, backup systems, supplier-risk assessments, emergency exercises, engineering reviews, and staff training.
This framework is predicated on the necessity for essential services to remain operational during disruptions caused by natural disasters, technical failures, sabotage, or other incidents.
This shift transforms resilience from optional corporate expenditure into an obligatory compliance cost.
<pA water utility company, hospital, food distributor, or digital-infrastructure provider must not only ensure the protection of key assets but also demonstrate the availability of alternative suppliers, backup capacity, and recovery procedures in the event of failures.
This situation may benefit specialized engineering and advisory firms capable of integrating operational, physical, and digital risk assessments.
The legislation will also enhance the significance of incident-management systems.
Critical operators are mandated to report significant incidents to authorities within 24 hours and provide further detailed information subsequently. Corporate fines for certain violations could amount to €20,000.
For insurers, this framework could enhance the quality of data available for underwriting critical assets.
Having documented resilience plans, conducting stress tests, and implementing continuity measures can facilitate easier assessment of operational risks.
The ultimate scale of the market will hinge on which companies are officially designated as critical and the specifics of the implementation rules.
However, much of the anticipated work is expected to be repetitive.
Risk assessments will require regular updates; emergency plans will need testing; employee training will be necessary; changes in suppliers and technical systems will occur.
For those designated operators, the approach to resilience is evolving from being a matter of best practice to becoming a recurring business expense.











