NIS2 Croatia: Zakon i Uredba o kibernetičkoj sigurnosti
Croatia transposed NIS2 early and in full, through the Zakon o kibernetičkoj sigurnosti (Official Gazette NN 14/24, in force 15 February 2024) and the Uredba o kibernetičkoj sigurnosti (NN 135/24, in force 30 November 2024). You do not register yourself — one of eight competent authorities categorises you and tells you. This page sets out who your authority is, the two-year audit you pay for yourself, the 24-hour clock, and fine ranges that carry a minimum as well as a maximum.
Introduction: NIS2 and the Croatian framework
Croatia was one of the earliest EU member states to transpose NIS2 in full. The framework rests on two instruments: the Zakon o kibernetičkoj sigurnosti (Cybersecurity Act) and the Uredba o kibernetičkoj sigurnosti (Cybersecurity Regulation), which between them cover categorisation, security requirements, audits, supervision and penalties for ključni (essential) and važni (important) entities.
The regime covers 19 sectors — 11 of high criticality and 8 other critical sectors — and Croatia added one the Directive does not have (see below). Three features set it apart from most member states, and all three are missing from the summaries in circulation.
Zakon i Uredba: the two instruments
The Zakon o kibernetičkoj sigurnosti was passed by the Croatian Parliament on 26 January 2024 and entered into force on 15 February 2024 (Official Gazette NN 14/24), transposing NIS2 and replacing the earlier NIS1-based framework.
The Uredba o kibernetičkoj sigurnosti was adopted by the Government on 21 November 2024 under Article 24 of the Act and has been in force since 30 November 2024 (NN 135/24). The Act sets the framework, the categorisation machinery, supervision and penalties; the Uredba carries the detailed security requirements and the incident-reporting deadlines. Reading only the Act will not tell you when to report.
Status
Transposed and fully in force since 30 November 2024, when the Uredba completed the framework. Croatia was among the first member states to finish.
Scope
19 sectors — 11 of high criticality (Annex I) and 8 other critical sectors (Annex II). Croatia publishes no entity count, so neither do we.
Who decides you are in scope
Not you. Annex III of the Act maps every sector to a named competent authority and a named CSIRT, and that authority categorises and notifies you.
How you find out you are in scope
Croatia does not operate self-registration. Under the Act, the competent authorities carry out the categorisation of entities and maintain the lists of ključni and važni subjects themselves, then notify the organisations concerned. If you have been waiting for a portal to register on, there isn't one.
The first round had a statutory deadline
The Act required the competent authorities to complete the first categorisation and deliver notification of it within one year of the Act entering into force — that is, by 15 February 2025. That date has passed.
The lists are refreshed
Authorities must review the lists of essential and important entities at least once every two years and update them where necessary. Being outside the first round does not mean being outside the regime permanently.
What if we have heard nothing?
Silence is not a determination of non-applicability. Identify your sector in Annex III, establish which authority is responsible for it, and approach them — particularly if your circumstances changed after the first categorisation round.
Changes must be reported
Once categorised, you carry reporting duties of your own: various submissions run on 30-day deadlines, and relevant changes must be notified within three months.
Scope & obligations
Croatia uses the NIS2 categories — ključni subjekti (essential) and važni subjekti (important) — and the Uredba then adds an unusual amount of detail on concrete controls, audits and self-assessments. The obligation that most distinguishes the Croatian regime is the recurring audit, which has its own section below.
Who is in scope?
- Annex I — 11 sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public sector, space.
- Annex II — 8 other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research — and the education system.
- Entities meeting the NIS2 size thresholds (medium-sized and above).
- Certain providers regardless of size — DNS services, TLD name registries, trust services and comparable digital infrastructure.
Core obligations
- Implement the risk-management measures set out in the Uredba.
- Essential entities: commission a cybersecurity audit at least every two years, at your own cost.
- Important entities: carry out a self-assessment at least every two years, at your own cost.
- Submit an early warning within 24 hours and a full notification within 72 hours of a significant incident.
- Notify affected recipients of your services within 72 hours of sending that notification.
- Manage supply-chain risk, and ensure management oversight and training.
Standards & frameworks
No certification is mandated. The binding requirements are those in the Uredba o kibernetičkoj sigurnosti, which is unusually prescriptive. ISO/IEC 27001 is a practical way to structure the work and to have evidence ready for the two-yearly audit, but it is not a substitute for the Uredba.
The two-year audit duty
This is the most operationally significant obligation in the Croatian regime, and the one most summaries reduce to the word “audits”. It is a recurring, self-funded duty with its own penalty.
| Entity | Duty | Frequency | Who pays |
|---|---|---|---|
| Ključni subjekt (essential) | Cybersecurity audit | At least once every two years | The entity |
| Važni subjekt (important) | Cybersecurity self-assessment | At least once every two years | The entity |
| Essential entities | Expert supervision by the competent authority | At least once every two years | — |
| Any supervised entity | Targeted cybersecurity audit, where ordered | As required | The supervised entity |
Incident reporting
The deadlines are in the Uredba, not the Act. Croatia runs the standard early-warning chain and, unusually, puts a matching obligation on the CSIRT to come back to you.
NIS2 timeline & key dates (Croatia)
Sector-specific notes for Croatia
- Energy: electricity, gas and related infrastructure operators are treated as essential entities with stringent obligations and close supervision.
- Transport: air, rail, road and maritime operators, including key logistics and port infrastructure, must comply with NIS2-aligned requirements.
- Healthcare: hospitals, clinics, laboratories and core e-health services are subject to strengthened cybersecurity and incident reporting duties.
- Water: drinking water and wastewater service providers are covered as essential or important entities under the Croatian framework.
- Finance: banking answers to HNB and financial market infrastructure to HANFA, both in the special-laws group — and both report incidents to the Nacionalni CERT rather than NCSC-HR.
- Public sector: the competent authority is ZSIS, the central state body for information security, not NCSC-HR.
- Education: Croatia added sustav obrazovanja to Annex II, a sector the Directive does not list. Education providers meeting the thresholds are in scope here even though they would not be elsewhere.
- Digital infrastructure & ICT providers: split across three authorities — HAKOM for public electronic communications networks and services, SDURDD for trust services, the science and education body for the .hr registry, and NCSC-HR for IXPs, DNS, cloud, data centres and CDNs.
Penalties: the EUR ranges
Croatia does something no other member state we have reviewed does: it sets a minimum as well as a maximum, on both the euro amount and the percentage of turnover. The Directive prescribes only ceilings. Article 101 of the Act brackets the range from both ends, and fines the responsible individual separately.
| Who | Fine range | Or, whichever is higher |
|---|---|---|
| Ključni subjekt (essential entity) | EUR 10,000 to EUR 10,000,000 | 0.5% to no more than 2% of total worldwide annual turnover in the preceding financial year |
| Važni subjekt (important entity) | EUR 5,000 to EUR 7,000,000 | 0.2% to no more than 1.4% of total worldwide annual turnover |
| The responsible person in an essential entity | EUR 1,000 to EUR 6,000 | Imposed in addition to the fine on the entity |
| The responsible person in an important entity | EUR 500 to EUR 3,000 | Imposed in addition to the fine on the entity |
| Further offence band | EUR 2,000 to EUR 20,000, with the responsible person from EUR 200 | — |
The floor is the part that matters
For a small in-scope entity, the EUR 10,000,000 ceiling is irrelevant — what applies is the EUR 10,000 minimum, or EUR 5,000 if you are an important entity. Those are the realistic figures, and they are the ones nobody publishes.
A minimum percentage is unusual
“0.5% to no more than 2%” means the turnover-based calculation also has a floor. Across the member states reviewed on this site, every other percentage is a ceiling only.
Named individuals are fined
Not a vague “management liability”: the responsible person carries a defined euro range of their own, alongside the entity's fine.
Missing an audit is enough
Failing to carry out the two-yearly audit or self-assessment is itself a listed infringement under this scale. You do not need to suffer an incident to be fined.
How Croatia differs
Six features that will not carry over from a NIS2 programme designed for Germany, Italy or the Nordics.
- Fines have a floor, including a minimum percentage of turnover. EUR 10,000 / 0.5% for essential entities, EUR 5,000 / 0.2% for important. Unique among the member states reviewed here.
- The responsible individual is fined separately, in a defined euro range.
- A cybersecurity audit every two years, at your own cost — and skipping it is a fineable offence by itself.
- No self-registration. One of eight competent authorities categorises you and notifies you; the first round was due by 15 February 2025.
- Two CSIRTs. Banking, financial market infrastructure and the .hr registry report to the Nacionalni CERT; everyone else to NCSC-HR.
- The education system is in scope, a sector the Directive's Annex II does not include.
| Croatian | English / meaning |
|---|---|
| Zakon o kibernetičkoj sigurnosti | The Cybersecurity Act, NN 14/24 |
| Uredba o kibernetičkoj sigurnosti | The Cybersecurity Regulation, NN 135/24 |
| ključni subjekt | Essential entity |
| važni subjekt | Important entity |
| kategorizacija subjekata | Categorisation — how you are brought into scope |
| stručni nadzor | Expert supervision |
| NCSC-HR | Nacionalni centar za kibernetičku sigurnost, within SOA |
| Nacionalni CERT | The second CSIRT — banking, financial market infrastructure, .hr registry |
| UVNS | Ured Vijeća za nacionalnu sigurnost — Single Point of Contact |
| sustav obrazovanja | The education system — Croatia's addition to Annex II |
If you are NOT in scope
Croatia is one of the few member states whose NIS2 law says something useful to organisations it does not regulate. The Act deliberately builds voluntary cyber-protection mechanisms for entities that are not categorised as essential or important.
The national detection system
The Act establishes a national system for detecting cyber threats and protecting cyberspace, open to wider use beyond the regulated population, with the stated aim of raising overall national capability and resilience.
Anonymous vulnerability reporting
Croatia operates a coordinated vulnerability disclosure framework under which any natural or legal person may report a vulnerability anonymously to the CSIRT vulnerability-detection coordinator. You do not need to be regulated, or identified, to use it.
How to prepare for NIS2 in Croatia
- Find your sector in Annex III and identify your competent authority and CSIRT. Everything else follows from it — who categorises you, who supervises you, and where incident reports go.
- Establish whether you were categorised. The first round was due by 15 February 2025. If you have heard nothing and believe you meet the thresholds, approach your authority rather than assuming you are out.
- Diarise the two-year audit now. Essential entities commission an audit, important entities self-assess, both at their own cost, and missing it is fineable on its own.
- Gap-assess against the Uredba, not against the Directive. It is the prescriptive instrument and it is what an audit will test.
- Build the 24-hour path, and know who answers. Early warning within 24 hours, notification within 72, recipients within a further 72 — and your CSIRT owes you a reply within 24 hours of the early warning.
- Check the education question if you are a school, university or training provider. Croatia put sustav obrazovanja in Annex II; most member states did not.
- Brief the individual who will be named. The responsible person carries a personal fine of EUR 1,000–6,000 in an essential entity, separate from the entity's own.
- Keep audit-ready evidence of risk assessments, measures, testing, training and incident handling — the cycle is recurring, not one-off.
Official links & resources
FAQ: NIS2 in Croatia
Has Croatia fully implemented NIS2?
Who enforces NIS2 in Croatia?
Will we be contacted, or do we register ourselves?
Do we need a specific certification?
What happens if we do nothing?
Do we have to pay for the cybersecurity audit ourselves?
Is the education sector really in scope in Croatia?
Sources & verification
Checked against primary sources on 10 August 2026. NCSC-HR publishes official English translations of both instruments, so the figures and deadlines here come from the statutory text rather than from secondary summaries.
- Zakon o kibernetičkoj sigurnosti, NN 14/24 — fine ranges (Article 101), the audit and self-assessment duties and who pays, the categorisation machinery and its one-year deadline, and Annex III, the sector-to-authority-to-CSIRT map reproduced above.
- Uredba o kibernetičkoj sigurnosti, NN 135/24 — the 24-hour early warning, the 72-hour notification, the CSIRT's 24-hour duty to respond and the recipient-notification deadline.
- HAKOM — its own statement of designation as competent authority for electronic communications, citing NN 14/24.
