Monaco's Coming Cybersecurity Law
Compliance·6 min read·18 August 2026

Monaco's Coming Cybersecurity Law

Monaco is preparing a national cybersecurity law modelled on NIS2. What businesses in the Principality can usefully do now, before the rules land.

Something Is Coming, and It Isn't Law Yet

Monaco has signalled its intention to build a national cybersecurity framework closely modelled on the European Union's NIS2 directive. That intention was made public at the Assises de la Cybersécurité and has been repeated since by people close to the file. Preparation sits with the Direction des Plateformes et des Ressources Numériques, and supervision would fall to the Agence Monégasque de Sécurité Numérique (AMSN).

Here is the honest state of play, and it matters more than any timeline you will read: there is no adopted Monegasque cybersecurity law today. What exists is a stated direction of travel, preparatory work inside government, and advisory commentary projecting entry into force somewhere around 2027. Those projections come from consultancies, not from the Journal de Monaco. Treat any specific date you see — including the ones in this article — as indicative rather than binding, and confirm the position with AMSN or a Monaco lawyer before you commit budget on the strength of it.

That caveat is not a reason to ignore the subject. It is a reason to do the cheap preparation now and skip the expensive scramble later.

Why a Non-EU State Would Copy an EU Directive

Monaco is not an EU member state, and EU directives do not apply here automatically. NIS2 has no direct legal force in the Principality. So why the alignment?

Because Monaco's economy is wired into Europe. Monegasque private banks, family offices, luxury houses and ICT providers all sit inside European supply chains. Under NIS2, EU-regulated companies must assess the security of their own suppliers — which means a French bank or an Italian manufacturer will increasingly ask its Monaco counterparty security questions with contractual teeth behind them. A national framework speaking the same vocabulary makes those conversations survivable.

There is also a sovereignty argument. Monaco has spent years building its own digital infrastructure and its own qualification schemes rather than importing them wholesale. A domestic cybersecurity law supervised by AMSN keeps that logic intact.

Who Would Realistically Be in Scope

Commentary on the file points to a covered population in the region of 300 to 400 entities — Monaco is small, and this is not a law aimed at every business in the Principality. Expect the familiar NIS2 split between essential and important entities, with the heavier obligations on the first group.

The likely profile is banks and financial institutions, healthcare, energy and water, transport, digital infrastructure and managed IT providers, public bodies, and larger operators in Monaco's signature sectors. A two-person consultancy or an independent restaurant almost certainly falls outside direct scope.

But direct scope is only half the picture, and for most readers of this article the smaller half. Supply-chain obligations flow downhill. If you are the agency, software vendor, or hosting partner serving a covered entity, you will be asked to evidence your own security posture — not by a regulator, but by your client's procurement team. That happens on the client's timetable, not the legislature's, and it is already happening.

The Obligations Worth Anticipating

If Monaco follows the NIS2 template — and every signal says it will — four things sit at the centre.

Governance with a named owner. NIS2 made management bodies accountable for cybersecurity risk measures, and no longer treats it as something delegated entirely to IT. Somebody senior has to be able to explain the risk picture.

Risk management measures. Policies, incident handling, business continuity, access control, multi-factor authentication, encryption. Monaco would likely map these to AMSN's existing national cybersecurity reference framework rather than inventing a parallel standard.

Incident reporting on a short clock. NIS2 runs a 24-hour early warning, a 72-hour notification, and a final report within one month. The 24-hour figure is the one to plan against, because it is far too short to work out who decides, who writes, and who holds the credentials.

Supply-chain security. Covered entities must consider the security of their suppliers and service providers — the mechanism that pushes requirements onto companies never named in the law.

The Overlap With Law No. 1.565 Is Your Shortcut

Monaco businesses already live with a 72-hour breach notification duty under Law No. 1.565 of 3 December 2024, supervised by the APDP. That is a different authority, a different trigger and a different report — a personal data breach is not the same thing as a cybersecurity incident, and one event can require both.

The overlap is in the plumbing, and the plumbing is most of the work. Who detects. Who decides it is notifiable. Who writes. Who signs. Where the contact details and log evidence live at 2am on a Sunday. Build that once, use it for both. Firms that have already done the APDP data protection groundwork are further along than they think.

What Is Worth Doing in the Next Twelve Months

None of this depends on the final text, and all of it pays for itself regardless:

  • Write down whether you are plausibly in scope — directly, or through a client who is. Two paragraphs, dated, revisited when the draft appears.
  • Fix the basics that every framework asks for. MFA everywhere, patching that actually happens, backups you have restored from at least once, and offboarding that removes access the same day. This is unglamorous and it is what audits find missing.
  • Know your own supply chain. Your CMS, plugins, hosting, payment provider, analytics, email platform. A dependency and vendor inventory is the prerequisite for every other control, and it belongs in an ongoing website maintenance and support arrangement rather than a one-off audit.
  • Rehearse a 24-hour response once. A one-hour tabletop exercise will expose more gaps than a hundred-page policy.
  • Get your infrastructure story straight. Where data is hosted, under whose jurisdiction, with what certifications — questions that increasingly shape web development decisions in Monaco long before any regulator asks.

Companies that treat this as a security-maturity project rather than a compliance project will be ready whenever the law lands, and will win procurement conversations in the meantime. Those waiting for the Journal de Monaco will have a few months to do a few years of work.

If you want a clear-eyed look at where your website, hosting and data flows would stand under a framework like this, get in touch — it is a short conversation and a useful one.

cybersecuritynis2complianceamsnmonaco
BSS Digital Agency

BSS Digital Agency

Digital agency based in Monaco. Web, apps, AI, marketing.

Get in touch