Uredba o kibernetičkoj sigurnosti
NIS2 says what you must achieve, never how you demonstrate it. Croatia answers with HR Uredba. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
The level is not yours to pick: it follows from the national risk assessment for your category of entity. And the regulation requires a periodic self-assessment (samoprocjena) — an obligation in its own right, not a preparation exercise.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the usual management-system route, but the levels and the self-assessment obligation come from the Uredba and have no ISO equivalent.
3 routes, chosen by scope and depth
Basic measures, aimed at the attacks that are globally prevalent rather than aimed at you specifically (art. 42).
Entities whose assessed risk is low
Adds protection against targeted attacks by adversaries of average capability. Cumulative: it contains the basic level.
Entities whose assessed risk is medium
Adds protection against sophisticated, well-resourced actors. Cumulative again.
Entities whose assessed risk is high
What it is built on
HR Uredba does not invent its own taxonomy. It sits on Zakon o kibernetičkoj sigurnosti.
Three progressive levels of risk-management measures, set out in Annex II of the regulation for all three levels at once (art. 41). A national risk assessment determines which level an entity must implement.
Why there is no unit-level mapping
The three levels are verified from the official text (arts. 38, 41 and 42). The individual measures sit in Annex II, which we have not yet transcribed from the Narodne novine text.
Not recorded yet at measure level. Secondary sources report thirteen measures in Annex II; we have not confirmed that against the official annex, so we do not publish the count as fact. The levels above are confirmed.
No stable public identifiers to map against
This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.
What you already have, for the same measure
Nobody in scope starts from nothing. HR Uredba is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) Risk analysis | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | 8.24 | SC |
| (i) HR, access, assets | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
- https://narodne-novine.nn.hr/clanci/sluzbeni/2024_11_135_2217.html
- https://ncsc.hr/hr/uredba-o-kibernetickoj-sigurnosti
We are not affiliated with Government of Croatia, with SOA / ZSIS as competent authority. HR Uredba and related marks belong to their owners.