Directive NIS2 European Union
NN 135/2024 · adopted 21 November 2024, published 22 November 2024

Uredba o kibernetičkoj sigurnosti

NIS2 says what you must achieve, never how you demonstrate it. Croatia answers with HR Uredba. If you operate there, this is what your regulator reads.

Published
Implementation routes
3
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

The level is not yours to pick: it follows from the national risk assessment for your category of entity. And the regulation requires a periodic self-assessment (samoprocjena) — an obligation in its own right, not a preparation exercise.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the usual management-system route, but the levels and the self-assessment obligation come from the Uredba and have no ISO equivalent.

Implementation routes

3 routes, chosen by scope and depth


Osnovna razina

Basic measures, aimed at the attacks that are globally prevalent rather than aimed at you specifically (art. 42).

Entities whose assessed risk is low

Srednja razina

Adds protection against targeted attacks by adversaries of average capability. Cumulative: it contains the basic level.

Entities whose assessed risk is medium

Napredna razina

Adds protection against sophisticated, well-resourced actors. Cumulative again.

Entities whose assessed risk is high

What it is built on

HR Uredba does not invent its own taxonomy. It sits on Zakon o kibernetičkoj sigurnosti.

Three progressive levels of risk-management measures, set out in Annex II of the regulation for all three levels at once (art. 41). A national risk assessment determines which level an entity must implement.

Mapping

Why there is no unit-level mapping


Basis

The three levels are verified from the official text (arts. 38, 41 and 42). The individual measures sit in Annex II, which we have not yet transcribed from the Narodne novine text.

Limit of this mapping

Not recorded yet at measure level. Secondary sources report thirteen measures in Annex II; we have not confirmed that against the official annex, so we do not publish the count as fact. The levels above are confirmed.

No stable public identifiers to map against

This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.

The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. HR Uredba is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to HR Uredba and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training 5.37 6.3 8.7 AT SI CM
(h) Cryptography 8.24 SC
(i) HR, access, assets 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Sources

We are not affiliated with Government of Croatia, with SOA / ZSIS as competent authority. HR Uredba and related marks belong to their owners.

Cart 0