NIS2 in Croatia
What binds you in Croatia is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Zakon o kibernetičkoj sigurnosti, with Uredba o kibernetičkoj sigurnosti (NN 135/2024)
The operative detail is in the Uredba, adopted 21 November 2024 and published in Narodne novine 135/2024, not in the act itself.
Uredba o kibernetičkoj sigurnosti — NN 135/2024
adopted 21 November 2024, published 22 November 2024, published by Government of Croatia, with SOA / ZSIS as competent authority. Built on Zakon o kibernetičkoj sigurnosti.
Croatia does have a structured framework, and the note we published here before was wrong to imply otherwise: the Uredba sets three progressive levels of risk-management measures (osnovna, srednja, napredna), listed in its Annex II for all three at once. Two things catch people out — the level is assigned by the national risk assessment rather than chosen, and the periodic self-assessment (samoprocjena) is an obligation in its own right, not preparation for one. Confirm which category of entity you are before scoping: the category decides the level, and the level decides the measures.
A label is not compliance
The level is not yours to pick: it follows from the national risk assessment for your category of entity. And the regulation requires a periodic self-assessment (samoprocjena) — an obligation in its own right, not a preparation exercise.
HR Uredba in full — levels, controls and what it does not cover →
Who supervises you
SOA / ZSIS is the competent authority designated by Croatia. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to CERT.hr, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, Croatia legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.