← Back to Reglyze
Transposed & Enforced

NIS2 in Croatia

Everything you need to know about the NIS2 directive in Hrvatska: transposition law, competent authority, fines, deadlines, and how Reglyze helps SMEs become compliant.

Croatia was one of the first EU member states to fully transpose NIS2: the Zakon o kibernetičkoj sigurnosti (NN 14/2024) has been in force since 15 February 2024, and the Uredba o kibernetičkoj sigurnosti (NN 135/2024) supplies the operative detail. The competent authority is ZSIS with the National Cyber Security Centre (NCSC-HR); subjects do not self-register — the authorities categorize essential (ključni) and important (važni) subjects and notify them. The distinctive Croatian feature is the assessment route: important subjects run the official ZSIS self-assessment (13 measures, 99 subsets, 137 controls, scored 1-5 against per-level thresholds) and file the Izjava o sukladnosti, while essential subjects face an external cybersecurity audit, each at least every two years.

Key facts at a glance

Transposition Law

Zakon o kibernetičkoj sigurnosti (Cybersecurity Act), NN 14/2024, implemented by the Uredba o kibernetičkoj sigurnosti (NN 135/2024)

Adopted / in force: 2024-02-14

Competent Authority

Zavod za sigurnost informacijskih sustava / Nacionalni centar za kibernetičku sigurnost (ZSIS / NCSC-HR)

https://www.zsis.hr/
Fines — Essential

EUR 10,000 up to EUR 10 million, or 0.5% up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher (čl. 101 ZKS)

Fines — Important

EUR 5,000 up to EUR 7 million, or 0.2% up to 1.4% of total worldwide annual turnover of the preceding financial year, whichever is higher (čl. 102 ZKS)

These ceilings come from the directive — see how NIS2 fines are calculated, recent enforcement cases and director personal liability.

Priority sectors for NIS2 in Croatia

NIS2 covers 18 sectors across Annex I (essential) and Annex II (important). These are the sectors where Croatia's transposition and ZSIS / NCSC-HR supervision focus most.

Energy, water, transport and health

High-criticality Annex I sectors concentrate Croatia's ključni subjekti, which face the external cybersecurity audit route (revizija kibernetičke sigurnosti) at least every two years and the higher čl. 101 fine band.

Digital infrastructure and ICT service management

Hosting, cloud, data-centre and managed service providers fall in scope, and the Uredba adds specific physical-security measures for digital-infrastructure subjects (Prilog III). Croatian MSPs also inherit supply-chain due-diligence demands from their in-scope clients.

Public administration and local government

State and local government bodies are covered, with NCSC-HR acting as their CSIRT; regional-development criteria pull significant county and city bodies into the important-subject tier.

Key deadlines

2024-02-15

The Zakon o kibernetičkoj sigurnosti (NN 14/2024) entered into force — one of the first full NIS2 transpositions in the EU.

2024-11

The implementing Uredba o kibernetičkoj sigurnosti (NN 135/2024) set the 13 risk-management measures, the ZSIS self-assessment methodology and the Izjava o sukladnosti form.

2025-02-15

Statutory deadline for the competent authorities to categorize essential and important subjects and notify them (one year from entry into force, čl. 110 ZKS).

ongoing

Important subjects repeat the ZSIS self-assessment at least every two years and file the Izjava o sukladnosti within 8 days of drawing it up; essential subjects undergo an external cybersecurity audit at least every two years.

Is your company in scope? Common Croatia scenarios

Two worked examples of how NIS2 scoping plays out in Croatia. Not sure where you land? Run the free NIS2 scope checker.

A 250-person Croatian electricity distributor
In scope — ključni subjekt (essential)

Energy is a high-criticality sector, so the authority categorizes the operator as a ključni subjekt and notifies it. Its compliance is verified through an external cybersecurity audit at least every two years, and significant incidents go to the competent CSIRT via the PiXi platform on the 24h/72h/30-day cadence.

A 70-employee Zagreb SaaS provider (EUR 12M turnover)
In scope — važni subjekt (important)

As a medium-sized digital-service provider it is categorized as a važni subjekt. It runs the ZSIS self-assessment against the 13 measures at its assigned level (typically osnovna), files the Izjava o sukladnosti within 8 days of drawing it up, repeats the exercise at least every two years, and keeps the documentation for 10 years.

What Croatia businesses need to know

  • Croatia transposed NIS2 early: the Zakon o kibernetičkoj sigurnosti (NN 14/2024) has been in force since 15 February 2024, with the Uredba o kibernetičkoj sigurnosti (NN 135/2024) carrying the technical detail.

  • Unlike most member states there is no self-registration: the competent authorities categorize subjects (ključni / važni) and notify them, with a special register kept at the Security and Intelligence Agency (SOA).

  • The compliance route splits by tier: KLJUČNI (essential) subjects undergo an external cybersecurity audit at least every two years, while VAŽNI (important) subjects run the ZSIS self-assessment and file the Izjava o sukladnosti (compliance statement, Prilog IV).

  • The ZSIS methodology assesses 13 measures through 99 subsets and 137 controls, each scored 1-5 on documentation and implementation, with a two-threshold conformity gate (per-control Pi and subset-average T) at the subject's assigned level (osnovna / srednja / napredna).

  • Significant incidents follow the 24-hour early warning (rano upozorenje), 72-hour notification (početna obavijest) and 30-day final report (završno izvješće) cadence, submitted via the national PiXi platform to NCSC-HR or Nacionalni CERT.

How ZSIS / NCSC-HR enforces NIS2 in Croatia

ZSIS / NCSC-HR is the central cybersecurity authority, with sector authorities conducting the categorization and a special register kept at the Security and Intelligence Agency (SOA). Supervision differentiates the tiers: essential subjects are audited externally at least every two years, while important subjects self-assess through the official ZSIS methodology and file the Izjava o sukladnosti; a non-conform self-assessment obliges the subject to adopt a remediation plan (plan daljnjeg postupanja) instead. Fines follow čl. 101-102 ZKS: EUR 10,000 to 10 million or 0.5-2% of worldwide turnover for essential subjects, EUR 5,000 to 7 million or 0.2-1.4% for important subjects, whichever is higher, with separate fines of EUR 1,000-6,000 for the responsible management persons.

NIS2 in Croatia: frequently asked questions

Is NIS2 in force in Croatia?
Yes, and earlier than in most of the EU. The Zakon o kibernetičkoj sigurnosti (NN 14/2024) has been in force since 15 February 2024, and the implementing Uredba o kibernetičkoj sigurnosti (NN 135/2024) has applied since late 2024. Categorization of subjects by the authorities was due within one year of entry into force.
Do Croatian companies register themselves as NIS2 entities?
No. Croatia has no self-registration: the competent authorities categorize essential (ključni) and important (važni) subjects and notify them, and a special register of subjects is kept at the Security and Intelligence Agency (SOA). After notification, subjects deliver their data and implement the risk-management measures.
What is the ZSIS self-assessment and the Izjava o sukladnosti?
Important subjects assess themselves against the official ZSIS methodology: 13 measures, 99 subsets and 137 controls, each scored 1-5 on documentation and implementation, judged against per-control (Pi) and subset-average (T) thresholds at the subject's assigned level (osnovna, srednja or napredna). If the result is conform (sukladan), the subject draws up the Izjava o sukladnosti (Prilog IV form) and delivers it to the competent authority within 8 days; if not, it must adopt a remediation plan instead. The cycle repeats at least every two years and the documentation is kept for 10 years.
What are the penalties in Croatia?
For essential subjects EUR 10,000 up to EUR 10 million, or 0.5% up to 2% of total worldwide annual turnover, whichever is higher (čl. 101 ZKS). For important subjects EUR 5,000 up to EUR 7 million, or 0.2% up to 1.4% (čl. 102 ZKS). Responsible management persons face separate fines of EUR 1,000 to 6,000.

Ready to become NIS2 compliant in Croatia?

Reglyze is the AI-powered NIS2 compliance platform built for European SMEs. Start free — scoping, gap assessment, and policy generation tailored to ZSIS / NCSC-HR requirements.