NIS2 · National implementation
NIS2 in Croatia
Croatia was the first member state to transpose, through the Zakon o kibernetičkoj sigurnosti (NN 14/2024), in force since 15 February 2024.
- National law
- Zakon o kibernetičkoj sigurnosti (NN 14/2024)
- Cybersecurity Act
- Status
- In force
- In force
- 15 February 2024
- Authority
- SOA / NCSC-HR
Supervision
The security-intelligence agency SOA, through its NCSC-HR (Nacionalni centar za kibernetičku sigurnost), is the central authority; CARNET's national CERT handles parts of the CSIRT role. Entities are categorised and notified through the national process, with detail in the implementing regulation.
What is specific to Croatia
Being first meant Croatia set patterns others watched: authority-led categorisation of entities (you are notified of your status), a single consolidated act covering NIS2, and early implementing regulation on the measures. Timelines for compliance run from an entity's categorisation decision.
Official sources
Primary references: the national statute book at narodne-novine.nn.hr and the national cybersecurity authority at www.uvns.hr.
NIS2 in Croatia: frequently asked questions
Last reviewed:
Related reading
Definitions
