NIS2 Country Guide

NIS2 Croatia: Zakon i Uredba o kibernetičkoj sigurnosti

Croatia transposed NIS2 early and in full, through the Zakon o kibernetičkoj sigurnosti (Official Gazette NN 14/24, in force 15 February 2024) and the Uredba o kibernetičkoj sigurnosti (NN 135/24, in force 30 November 2024). You do not register yourself — one of eight competent authorities categorises you and tells you. This page sets out who your authority is, the two-year audit you pay for yourself, the 24-hour clock, and fine ranges that carry a minimum as well as a maximum.

Croatia Zakon in force: 15 Feb 2024 Uredba in force: 30 Nov 2024 Audit every 2 years Last updated: 10 August 2026

Introduction: NIS2 and the Croatian framework

Croatia was one of the earliest EU member states to transpose NIS2 in full. The framework rests on two instruments: the Zakon o kibernetičkoj sigurnosti (Cybersecurity Act) and the Uredba o kibernetičkoj sigurnosti (Cybersecurity Regulation), which between them cover categorisation, security requirements, audits, supervision and penalties for ključni (essential) and važni (important) entities.

The regime covers 19 sectors — 11 of high criticality and 8 other critical sectors — and Croatia added one the Directive does not have (see below). Three features set it apart from most member states, and all three are missing from the summaries in circulation.

The three things to know first. You do not self-register — a competent authority categorises you and notifies you, and the first round was legally due by 15 February 2025. Essential entities must commission a cybersecurity audit every two years and pay for it themselves, and failing to do so is a fineable offence in its own right. And Croatia's fines carry a minimum as well as a maximum — including a minimum percentage of turnover, which no other member state we have reviewed applies.
Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

Zakon i Uredba: the two instruments

The Zakon o kibernetičkoj sigurnosti was passed by the Croatian Parliament on 26 January 2024 and entered into force on 15 February 2024 (Official Gazette NN 14/24), transposing NIS2 and replacing the earlier NIS1-based framework.

The Uredba o kibernetičkoj sigurnosti was adopted by the Government on 21 November 2024 under Article 24 of the Act and has been in force since 30 November 2024 (NN 135/24). The Act sets the framework, the categorisation machinery, supervision and penalties; the Uredba carries the detailed security requirements and the incident-reporting deadlines. Reading only the Act will not tell you when to report.

Status

Transposed and fully in force since 30 November 2024, when the Uredba completed the framework. Croatia was among the first member states to finish.

Scope

19 sectors — 11 of high criticality (Annex I) and 8 other critical sectors (Annex II). Croatia publishes no entity count, so neither do we.

Who decides you are in scope

Not you. Annex III of the Act maps every sector to a named competent authority and a named CSIRT, and that authority categorises and notifies you.

How you find out you are in scope

Croatia does not operate self-registration. Under the Act, the competent authorities carry out the categorisation of entities and maintain the lists of ključni and važni subjects themselves, then notify the organisations concerned. If you have been waiting for a portal to register on, there isn't one.

The first round had a statutory deadline

The Act required the competent authorities to complete the first categorisation and deliver notification of it within one year of the Act entering into force — that is, by 15 February 2025. That date has passed.

The lists are refreshed

Authorities must review the lists of essential and important entities at least once every two years and update them where necessary. Being outside the first round does not mean being outside the regime permanently.

What if we have heard nothing?

Silence is not a determination of non-applicability. Identify your sector in Annex III, establish which authority is responsible for it, and approach them — particularly if your circumstances changed after the first categorisation round.

Changes must be reported

Once categorised, you carry reporting duties of your own: various submissions run on 30-day deadlines, and relevant changes must be notified within three months.

Scope & obligations

Croatia uses the NIS2 categories — ključni subjekti (essential) and važni subjekti (important) — and the Uredba then adds an unusual amount of detail on concrete controls, audits and self-assessments. The obligation that most distinguishes the Croatian regime is the recurring audit, which has its own section below.

Who is in scope?

  • Annex I — 11 sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public sector, space.
  • Annex II — 8 other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research — and the education system.
  • Entities meeting the NIS2 size thresholds (medium-sized and above).
  • Certain providers regardless of size — DNS services, TLD name registries, trust services and comparable digital infrastructure.

Core obligations

  • Implement the risk-management measures set out in the Uredba.
  • Essential entities: commission a cybersecurity audit at least every two years, at your own cost.
  • Important entities: carry out a self-assessment at least every two years, at your own cost.
  • Submit an early warning within 24 hours and a full notification within 72 hours of a significant incident.
  • Notify affected recipients of your services within 72 hours of sending that notification.
  • Manage supply-chain risk, and ensure management oversight and training.

Standards & frameworks

No certification is mandated. The binding requirements are those in the Uredba o kibernetičkoj sigurnosti, which is unusually prescriptive. ISO/IEC 27001 is a practical way to structure the work and to have evidence ready for the two-yearly audit, but it is not a substitute for the Uredba.

Croatia added a sector. The Directive's Annex II lists seven sectors; Croatia's lists eight, adding sustav obrazovanja — the education system. Schools, universities and education providers meeting the size thresholds should not assume they are outside NIS2 in Croatia merely because they would be in another member state.

The two-year audit duty

This is the most operationally significant obligation in the Croatian regime, and the one most summaries reduce to the word “audits”. It is a recurring, self-funded duty with its own penalty.

Entity Duty Frequency Who pays
Ključni subjekt (essential) Cybersecurity audit At least once every two years The entity
Važni subjekt (important) Cybersecurity self-assessment At least once every two years The entity
Essential entities Expert supervision by the competent authority At least once every two years
Any supervised entity Targeted cybersecurity audit, where ordered As required The supervised entity
Failing to do it is a separate offence. The Act lists “fails to perform a cybersecurity audit at least once every two years” and “fails to perform a self-assessment of cybersecurity at least once every two years” among the infringements carrying the full fine range in the penalties section below. An organisation can be entirely secure and still be fined for not having audited itself on schedule. Put the two-year cycle in a calendar, not a policy document.

Incident reporting

The deadlines are in the Uredba, not the Act. Croatia runs the standard early-warning chain and, unusually, puts a matching obligation on the CSIRT to come back to you.

Within 24 hours — submit an early warning of a significant incident to your competent CSIRT, without delay. You can use it to request incident-mitigation guidance.
Within 24 hours of your early warningthe CSIRT must respond, including with possible incident-mitigation measures if you asked for them in the early warning.
Within 72 hours — submit the full incident notification to the competent CSIRT.
Within 72 hours of sending that notification — inform the recipients of your services who could be affected, in clear and easily understandable terms.
Know which CSIRT is yours before you need it. Croatia has two. Most sectors report to NCSC-HR; banking, financial market infrastructure and the national TLD registry report to the Nacionalni CERT. Annex III of the Act assigns one to every sector, and the table in the next section reproduces the split.

Competent authorities & CSIRTs

Croatia does not run a single-regulator model. Annex III of the ActPopis nadležnosti u području kibernetičke sigurnosti — maps every sector and subsector to a named competent authority and a named CSIRT. There are eight competent authorities in two statutory groups, plus two CSIRTs. Identifying yours is the first practical step, because it determines who categorises you, who supervises you and where your incident reports go.

RoleAuthorityNotes
Central authority — most sectors NCSC-HR — Nacionalni centar za kibernetičku sigurnost, established within the Security and Intelligence Agency (SOA) Competent authority for energy, rail/road/water transport, health, drinking water, waste water, internet exchange points, DNS, cloud, data centres, CDNs, B2B ICT service management, space, postal, waste, chemicals, food, manufacturing, research and education. Also the CSIRT for all of them.
Public sector ZSIS — the central state body for information security Competent authority for the public sector. CSIRT remains NCSC-HR.
Electronic communications HAKOM — Hrvatska regulatorna agencija za mrežne djelatnosti Competent authority for providers of public electronic communications networks and publicly available electronic communications services. Carries out categorisation, maintains the lists and conducts expert supervision for its sector. CSIRT remains NCSC-HR.
Trust services SDURDD — the state body for digital society development Competent authority for trust service providers. CSIRT remains NCSC-HR.
National TLD registry The state body competent for science and education Competent authority for the .hr registry. CSIRT is the Nacionalni CERT. Where a domain-name registrar ignores warnings or orders, this body asks CARNET to temporarily suspend the registrar's authorisation.
Banking (special-laws group) HNB — Hrvatska narodna banka CSIRT is the Nacionalni CERT, not NCSC-HR.
Financial market infrastructure (special-laws group) HANFA — Hrvatska agencija za nadzor financijskih usluga CSIRT is the Nacionalni CERT, not NCSC-HR.
Air transport (special-laws group) Hrvatska agencija za civilno zrakoplovstvo — the Civil Aviation Agency CSIRT is NCSC-HR.
Single Point of Contact UVNS — Ured Vijeća za nacionalnu sigurnost Croatia's SPOC towards the EU and other member states.

NIS2 timeline & key dates (Croatia)

26 Jan 2024 — the Croatian Parliament passes the Zakon o kibernetičkoj sigurnosti.
15 Feb 2024 — the Act enters into force (NN 14/24), transposing NIS2.
21 Nov 2024 — the Government adopts the Uredba under Article 24 of the Act.
30 Nov 2024 — the Uredba enters into force (NN 135/24). The framework is complete.
15 Feb 2025statutory deadline for the competent authorities to complete the first categorisation of entities and deliver notification of it. One year from entry into force. This date has passed.
Every two years thereafter — authorities review and update the lists of essential and important entities; entities audit or self-assess on the same cycle.

Sector-specific notes for Croatia

  • Energy: electricity, gas and related infrastructure operators are treated as essential entities with stringent obligations and close supervision.
  • Transport: air, rail, road and maritime operators, including key logistics and port infrastructure, must comply with NIS2-aligned requirements.
  • Healthcare: hospitals, clinics, laboratories and core e-health services are subject to strengthened cybersecurity and incident reporting duties.
  • Water: drinking water and wastewater service providers are covered as essential or important entities under the Croatian framework.
  • Finance: banking answers to HNB and financial market infrastructure to HANFA, both in the special-laws group — and both report incidents to the Nacionalni CERT rather than NCSC-HR.
  • Public sector: the competent authority is ZSIS, the central state body for information security, not NCSC-HR.
  • Education: Croatia added sustav obrazovanja to Annex II, a sector the Directive does not list. Education providers meeting the thresholds are in scope here even though they would not be elsewhere.
  • Digital infrastructure & ICT providers: split across three authorities — HAKOM for public electronic communications networks and services, SDURDD for trust services, the science and education body for the .hr registry, and NCSC-HR for IXPs, DNS, cloud, data centres and CDNs.

Penalties: the EUR ranges

Croatia does something no other member state we have reviewed does: it sets a minimum as well as a maximum, on both the euro amount and the percentage of turnover. The Directive prescribes only ceilings. Article 101 of the Act brackets the range from both ends, and fines the responsible individual separately.

Who Fine range Or, whichever is higher
Ključni subjekt (essential entity) EUR 10,000 to EUR 10,000,000 0.5% to no more than 2% of total worldwide annual turnover in the preceding financial year
Važni subjekt (important entity) EUR 5,000 to EUR 7,000,000 0.2% to no more than 1.4% of total worldwide annual turnover
The responsible person in an essential entity EUR 1,000 to EUR 6,000 Imposed in addition to the fine on the entity
The responsible person in an important entity EUR 500 to EUR 3,000 Imposed in addition to the fine on the entity
Further offence band EUR 2,000 to EUR 20,000, with the responsible person from EUR 200

The floor is the part that matters

For a small in-scope entity, the EUR 10,000,000 ceiling is irrelevant — what applies is the EUR 10,000 minimum, or EUR 5,000 if you are an important entity. Those are the realistic figures, and they are the ones nobody publishes.

A minimum percentage is unusual

“0.5% to no more than 2%” means the turnover-based calculation also has a floor. Across the member states reviewed on this site, every other percentage is a ceiling only.

Named individuals are fined

Not a vague “management liability”: the responsible person carries a defined euro range of their own, alongside the entity's fine.

Missing an audit is enough

Failing to carry out the two-yearly audit or self-assessment is itself a listed infringement under this scale. You do not need to suffer an incident to be fined.

How Croatia differs

Six features that will not carry over from a NIS2 programme designed for Germany, Italy or the Nordics.

  • Fines have a floor, including a minimum percentage of turnover. EUR 10,000 / 0.5% for essential entities, EUR 5,000 / 0.2% for important. Unique among the member states reviewed here.
  • The responsible individual is fined separately, in a defined euro range.
  • A cybersecurity audit every two years, at your own cost — and skipping it is a fineable offence by itself.
  • No self-registration. One of eight competent authorities categorises you and notifies you; the first round was due by 15 February 2025.
  • Two CSIRTs. Banking, financial market infrastructure and the .hr registry report to the Nacionalni CERT; everyone else to NCSC-HR.
  • The education system is in scope, a sector the Directive's Annex II does not include.
CroatianEnglish / meaning
Zakon o kibernetičkoj sigurnostiThe Cybersecurity Act, NN 14/24
Uredba o kibernetičkoj sigurnostiThe Cybersecurity Regulation, NN 135/24
ključni subjektEssential entity
važni subjektImportant entity
kategorizacija subjekataCategorisation — how you are brought into scope
stručni nadzorExpert supervision
NCSC-HRNacionalni centar za kibernetičku sigurnost, within SOA
Nacionalni CERTThe second CSIRT — banking, financial market infrastructure, .hr registry
UVNSUred Vijeća za nacionalnu sigurnost — Single Point of Contact
sustav obrazovanjaThe education system — Croatia's addition to Annex II

If you are NOT in scope

Croatia is one of the few member states whose NIS2 law says something useful to organisations it does not regulate. The Act deliberately builds voluntary cyber-protection mechanisms for entities that are not categorised as essential or important.

The national detection system

The Act establishes a national system for detecting cyber threats and protecting cyberspace, open to wider use beyond the regulated population, with the stated aim of raising overall national capability and resilience.

Anonymous vulnerability reporting

Croatia operates a coordinated vulnerability disclosure framework under which any natural or legal person may report a vulnerability anonymously to the CSIRT vulnerability-detection coordinator. You do not need to be regulated, or identified, to use it.

Why this matters commercially even if you are out of scope. Croatian essential and important entities must manage supply-chain risk, so their suppliers are already receiving security clauses and audit rights in contracts. Being outside the categorised population does not keep NIS2 out of your customer agreements.

How to prepare for NIS2 in Croatia

  1. Find your sector in Annex III and identify your competent authority and CSIRT. Everything else follows from it — who categorises you, who supervises you, and where incident reports go.
  2. Establish whether you were categorised. The first round was due by 15 February 2025. If you have heard nothing and believe you meet the thresholds, approach your authority rather than assuming you are out.
  3. Diarise the two-year audit now. Essential entities commission an audit, important entities self-assess, both at their own cost, and missing it is fineable on its own.
  4. Gap-assess against the Uredba, not against the Directive. It is the prescriptive instrument and it is what an audit will test.
  5. Build the 24-hour path, and know who answers. Early warning within 24 hours, notification within 72, recipients within a further 72 — and your CSIRT owes you a reply within 24 hours of the early warning.
  6. Check the education question if you are a school, university or training provider. Croatia put sustav obrazovanja in Annex II; most member states did not.
  7. Brief the individual who will be named. The responsible person carries a personal fine of EUR 1,000–6,000 in an essential entity, separate from the entity's own.
  8. Keep audit-ready evidence of risk assessments, measures, testing, training and incident handling — the cycle is recurring, not one-off.

Official links & resources

FAQ: NIS2 in Croatia

Has Croatia fully implemented NIS2?
Yes. NIS2 has been transposed via the Cybersecurity Act (in force since 15 February 2024) and the Cybersecurity Regulation (in force since 30 November 2024).
Who enforces NIS2 in Croatia?
It depends on your sector. NCSC-HR (within SOA) is the central authority and covers most sectors, but ZSIS handles the public sector, HAKOM electronic communications, SDURDD trust services, and the science and education body the .hr registry. Banking answers to HNB, financial market infrastructure to HANFA and air transport to the Civil Aviation Agency. UVNS is the Single Point of Contact. Annex III of the Act maps all of it.
Will we be contacted, or do we register ourselves?
You are contacted. Croatia has no self-registration — the competent authorities carry out the categorisation, maintain the lists of ključni and važni subjects and notify you. The first round was legally due by 15 February 2025, and the lists are reviewed at least every two years. If you believe you meet the thresholds and have heard nothing, approach the authority for your sector rather than assuming you are outside.
Do we need a specific certification?
Certification (e.g. ISO/IEC 27001) is not explicitly mandated, but it can significantly help to structure your security measures and demonstrate compliance with the detailed requirements in the Regulation.
What happens if we do nothing?
Fines start at a floor, not zero: EUR 10,000 for an essential entity and EUR 5,000 for an important one, rising to EUR 10,000,000 or 2% of worldwide turnover, with the responsible individual fined EUR 1,000–6,000 separately. And you do not need to have suffered an incident — failing to carry out the two-yearly audit or self-assessment is a listed infringement in its own right.
Do we have to pay for the cybersecurity audit ourselves?
Yes. The Act states that the costs of the cybersecurity audit are borne by the entity, and the same applies to the self-assessment for important entities and to any targeted audit ordered during supervision. Essential entities must audit at least once every two years; important entities self-assess on the same cycle.
Is the education sector really in scope in Croatia?
Croatia's Annex II includes sustav obrazovanja — the education system — which the Directive's own Annex II does not list. Education providers meeting the size thresholds should therefore check their position in Croatia even if they are out of scope in other member states.

Sources & verification

Checked against primary sources on 10 August 2026. NCSC-HR publishes official English translations of both instruments, so the figures and deadlines here come from the statutory text rather than from secondary summaries.

  • Zakon o kibernetičkoj sigurnosti, NN 14/24 — fine ranges (Article 101), the audit and self-assessment duties and who pays, the categorisation machinery and its one-year deadline, and Annex III, the sector-to-authority-to-CSIRT map reproduced above.
  • Uredba o kibernetičkoj sigurnosti, NN 135/24 — the 24-hour early warning, the 72-hour notification, the CSIRT's 24-hour duty to respond and the recipient-notification deadline.
  • HAKOM — its own statement of designation as competent authority for electronic communications, citing NN 14/24.
A note on method, if you are checking this yourself. The “Ministry of Justice and Public Administration” is sometimes listed among Croatia's competent authorities; it appears nowhere in the Act. Verifying that is harder than it looks, and the reason is worth recording: the Act designates authorities by function (regulatorno tijelo za mrežne djelatnosti) rather than by acronym, and where it uses names it uses full legal names — so searching the English translation for “HAKOM” returns nothing even though HAKOM is unambiguously a designated competent authority.
What we deliberately do not state. An entity count — no Croatian authority publishes a figure and the “thousands of entities” claim that circulates is unsourced, so we give the sector count instead. A subsector count — “15 subsectors” cannot be verified against the annexes, while “19 sectors” is confirmed as 11 plus 8.
Information provided for general guidance and current at 10 August 2026. Always consult the Zakon o kibernetičkoj sigurnosti, the Uredba o kibernetičkoj sigurnosti and NCSC-HR guidance, as well as legal counsel, for definitive NIS2 compliance requirements.