Choose the relevant starting point. Each engagement confirms applicability, the current rules and the work VLK will perform; this page does not claim completed implementations or certification across every framework.
Serbia · Law
Serbian Information Security Law
Serbia’s Information Security Law (Official Gazette 91/2025) addresses ICT security responsibilities and measures. Applicability, transition provisions and implementing acts must be checked for the particular organization.
How VLK can help
Scope and readiness review, risk assessment, security documentation, assigned responsibilities and an evidence-based improvement plan.
Ministry: legislation
Discuss your requirementsEuropean Union · Directive
NIS2
Directive (EU) 2022/2555 sets a cybersecurity framework implemented through national law. Entity type, size, sector and national rules affect scope; supply-chain requests do not automatically make every supplier directly regulated.
How VLK can help
Governance and risk-management gap review, incident-readiness processes, supplier-security evidence and a prioritized implementation roadmap.
Official directive
Discuss your requirementsEuropean Union · Regulation
DORA
Regulation (EU) 2022/2554 concerns digital operational resilience in the financial sector and includes ICT third-party risk. The client’s entity type and role determine the relevant requirements.
How VLK can help
ICT risk and governance readiness, evidence organization, supplier-risk processes and resilience planning within an agreed scope.
Official regulation
Discuss your requirementsInternational · Standard
ISO/IEC 27001:2022
A requirements standard for an information security management system. Readiness support and accredited certification are different activities; applicable amendments and audit criteria should be confirmed at scoping.
How VLK can help
ISMS scope, gap assessment, risk assessment and treatment planning, policy structure and preparation of implementation evidence. Certification remains with the certification body.
ISO standard overview
Discuss your requirementsVoluntary · Framework
NIST CSF 2.0
A framework for organizing cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond and Recover. It is not a certification scheme or a substitute for applicable law.
How VLK can help
Current and target profiles, prioritized gaps, management reporting and a roadmap aligned with business risk.
NIST framework
Discuss your requirementsSerbia / EU where applicable · Data protection
Serbian Personal Data Protection Law & GDPR
Serbia’s personal data protection law and the EU GDPR have distinct scope rules. Security measures are one part of data protection, alongside lawful processing and individual rights.
How VLK can help
Security-control and risk review, data-flow discovery and evidence coordination with the client’s legal adviser or privacy lead. Formal legal opinions are outside this advisory scope.
GDPR official text
Discuss your requirementsReferences checked 12 September 2026. Country-specific implementation, sector rules and applicability are confirmed for each engagement. Legal interpretation and independent certification require the relevant specialists.