This paper aims to examine cybersecurity governance in the Western Balkans through the combined lens of NIS2 alignment, institutional capacity and critical infrastructure protection. It treats cybersecurity as a regulatory and governance problem rather than as a purely technical domain.
The study adopts a comparative exploratory regulatory case-study design covering Albania, Bosnia and Herzegovina, Kosovo, Montenegro, North Macedonia and Serbia. The empirical basis is a document corpus composed of cybersecurity laws, national strategies, CSIRT/CERT institutional sources, critical infrastructure documents, EU enlargement reports, NIS2-related material and regional policy evidence.
The framework identifies a structured basis for comparing formal legal alignment with operational governance capacity. The most relevant differences concern institutional fragmentation, competent-authority design, incident-reporting arrangements, CSIRT/CERT maturity and the integration of cybersecurity into critical infrastructure protection.
The paper provides a policy-relevant framework for accession-oriented cybersecurity reforms, especially where legal transposition must be connected to enforcement, coordination and cross-border resilience.
The paper develops a comparative regulatory framework for analysing NIS2-aligned cybersecurity governance capacity in the Western Balkans as a regional governance challenge.
