NIS2 · National implementation

NIS2 in Croatia

Croatia was the first member state to transpose, through the Zakon o kibernetičkoj sigurnosti (NN 14/2024), in force since 15 February 2024.

National law
Zakon o kibernetičkoj sigurnosti (NN 14/2024)
Cybersecurity Act
Status
In force
In force
15 February 2024
Authority
SOA / NCSC-HR

Supervision

The security-intelligence agency SOA, through its NCSC-HR (Nacionalni centar za kibernetičku sigurnost), is the central authority; CARNET's national CERT handles parts of the CSIRT role. Entities are categorised and notified through the national process, with detail in the implementing regulation.

What is specific to Croatia

Being first meant Croatia set patterns others watched: authority-led categorisation of entities (you are notified of your status), a single consolidated act covering NIS2, and early implementing regulation on the measures. Timelines for compliance run from an entity's categorisation decision.

Official sources

Primary references: the national statute book at narodne-novine.nn.hr and the national cybersecurity authority at www.uvns.hr.

NIS2 in Croatia: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states