Everything you need to know about the NIS2 directive in Hrvatska: transposition law, competent authority, fines, deadlines, and how Reglyze helps SMEs become compliant.
Croatia was one of the first EU member states to fully transpose NIS2: the Zakon o kibernetičkoj sigurnosti (NN 14/2024) has been in force since 15 February 2024, and the Uredba o kibernetičkoj sigurnosti (NN 135/2024) supplies the operative detail. The competent authority is ZSIS with the National Cyber Security Centre (NCSC-HR); subjects do not self-register — the authorities categorize essential (ključni) and important (važni) subjects and notify them. The distinctive Croatian feature is the assessment route: important subjects run the official ZSIS self-assessment (13 measures, 99 subsets, 137 controls, scored 1-5 against per-level thresholds) and file the Izjava o sukladnosti, while essential subjects face an external cybersecurity audit, each at least every two years.
Zakon o kibernetičkoj sigurnosti (Cybersecurity Act), NN 14/2024, implemented by the Uredba o kibernetičkoj sigurnosti (NN 135/2024)
Adopted / in force: 2024-02-14
Zavod za sigurnost informacijskih sustava / Nacionalni centar za kibernetičku sigurnost (ZSIS / NCSC-HR)
https://www.zsis.hr/EUR 10,000 up to EUR 10 million, or 0.5% up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher (čl. 101 ZKS)
EUR 5,000 up to EUR 7 million, or 0.2% up to 1.4% of total worldwide annual turnover of the preceding financial year, whichever is higher (čl. 102 ZKS)
These ceilings come from the directive — see how NIS2 fines are calculated, recent enforcement cases and director personal liability.
NIS2 covers 18 sectors across Annex I (essential) and Annex II (important). These are the sectors where Croatia's transposition and ZSIS / NCSC-HR supervision focus most.
High-criticality Annex I sectors concentrate Croatia's ključni subjekti, which face the external cybersecurity audit route (revizija kibernetičke sigurnosti) at least every two years and the higher čl. 101 fine band.
Hosting, cloud, data-centre and managed service providers fall in scope, and the Uredba adds specific physical-security measures for digital-infrastructure subjects (Prilog III). Croatian MSPs also inherit supply-chain due-diligence demands from their in-scope clients.
State and local government bodies are covered, with NCSC-HR acting as their CSIRT; regional-development criteria pull significant county and city bodies into the important-subject tier.
2024-02-15
The Zakon o kibernetičkoj sigurnosti (NN 14/2024) entered into force — one of the first full NIS2 transpositions in the EU.
2024-11
The implementing Uredba o kibernetičkoj sigurnosti (NN 135/2024) set the 13 risk-management measures, the ZSIS self-assessment methodology and the Izjava o sukladnosti form.
2025-02-15
Statutory deadline for the competent authorities to categorize essential and important subjects and notify them (one year from entry into force, čl. 110 ZKS).
ongoing
Important subjects repeat the ZSIS self-assessment at least every two years and file the Izjava o sukladnosti within 8 days of drawing it up; essential subjects undergo an external cybersecurity audit at least every two years.
Two worked examples of how NIS2 scoping plays out in Croatia. Not sure where you land? Run the free NIS2 scope checker.
Energy is a high-criticality sector, so the authority categorizes the operator as a ključni subjekt and notifies it. Its compliance is verified through an external cybersecurity audit at least every two years, and significant incidents go to the competent CSIRT via the PiXi platform on the 24h/72h/30-day cadence.
As a medium-sized digital-service provider it is categorized as a važni subjekt. It runs the ZSIS self-assessment against the 13 measures at its assigned level (typically osnovna), files the Izjava o sukladnosti within 8 days of drawing it up, repeats the exercise at least every two years, and keeps the documentation for 10 years.
Croatia transposed NIS2 early: the Zakon o kibernetičkoj sigurnosti (NN 14/2024) has been in force since 15 February 2024, with the Uredba o kibernetičkoj sigurnosti (NN 135/2024) carrying the technical detail.
Unlike most member states there is no self-registration: the competent authorities categorize subjects (ključni / važni) and notify them, with a special register kept at the Security and Intelligence Agency (SOA).
The compliance route splits by tier: KLJUČNI (essential) subjects undergo an external cybersecurity audit at least every two years, while VAŽNI (important) subjects run the ZSIS self-assessment and file the Izjava o sukladnosti (compliance statement, Prilog IV).
The ZSIS methodology assesses 13 measures through 99 subsets and 137 controls, each scored 1-5 on documentation and implementation, with a two-threshold conformity gate (per-control Pi and subset-average T) at the subject's assigned level (osnovna / srednja / napredna).
Significant incidents follow the 24-hour early warning (rano upozorenje), 72-hour notification (početna obavijest) and 30-day final report (završno izvješće) cadence, submitted via the national PiXi platform to NCSC-HR or Nacionalni CERT.
ZSIS / NCSC-HR is the central cybersecurity authority, with sector authorities conducting the categorization and a special register kept at the Security and Intelligence Agency (SOA). Supervision differentiates the tiers: essential subjects are audited externally at least every two years, while important subjects self-assess through the official ZSIS methodology and file the Izjava o sukladnosti; a non-conform self-assessment obliges the subject to adopt a remediation plan (plan daljnjeg postupanja) instead. Fines follow čl. 101-102 ZKS: EUR 10,000 to 10 million or 0.5-2% of worldwide turnover for essential subjects, EUR 5,000 to 7 million or 0.2-1.4% for important subjects, whichever is higher, with separate fines of EUR 1,000-6,000 for the responsible management persons.
Primary references for NIS2 in Croatia — verify the latest text and deadlines directly with the authority.