Purpose This paper aims to examine cybersecurity governance in the Western Balkans through the combined lens of NIS2 alignment, institutional capacity and critical infrastructure protection. It treats cybersecurity as a regulatory and governance problem rather than as a purely technical domain. Design/methodology/approach The study adopts a comparative exploratory regulatory case-study design covering Albania, Bosnia and Herzegovina, Kosovo, Montenegro, North Macedonia and Serbia. The empirical basis is a document corpus composed of cybersecurity laws, national strategies, CSIRT/CERT institutional sources, critical infrastructure documents, EU enlargement reports, NIS2-related material and regional policy evidence. Findings The framework identifies a structured basis for comparing formal legal alignment with operational governance capacity. The most relevant differences concern institutional fragmentation, competent-authority design, incident-reporting arrangements, CSIRT/CERT maturity and the integration of cybersecurity into critical infrastructure protection. Practical implications The paper provides a policy-relevant framework for accession-oriented cybersecurity reforms, especially where legal transposition must be connected to enforcement, coordination and cross-border resilience. Originality/value The paper develops a comparative regulatory framework for analysing NIS2-aligned cybersecurity governance capacity in the Western Balkans as a regional governance challenge.
No takes yet. Share an insight, caveat, or question.
Stefan Atanasov Raychev (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: