RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU
Cyber security and artificial intelligence advisory

We know what is required of you and how it is proven.

We work with essential and important entities on the Cyber Security Act, on artificial intelligence and on personal data protection. We say who does what, in what order, and what proves it.

  • CATEGORISED IMPORTANT ENTITY UNDER THE ACT

Five areas, one set of records

In practice they keep overlapping: the same asset inventory, the same risk register, the same records.

Sectors we cover

Sector and size decide the category, with exceptions. In healthcare and public administration the test is the activity, not the size.

SOA · competent authority outside state administration   UVNS · expert supervision of state administration bodies   NCSC-HR · incident reporting   AZOP · personal data breaches

Thirteen measures, one piece of evidence at a time

  1. 01

    We map the current state

    A score for each of the 137 controls and a list of missing evidence. Two to three weeks.

  2. 02

    We close the gaps

    Policies, procedures, the risk register and the records behind every measure.

  3. 03

    We review the file before the auditor

    We go through the documentation the way the auditor will, before they arrive.

See all thirteen measures of the Act
WHAT YOU GET
  • A gap analysis report scored by sub-measure and control
  • An asset register and threat catalogue fitted to your sector
  • A risk register, a matrix following the NCSC-HR guidance and a risk treatment plan
  • A compliance plan with priorities, owners and resource estimates
  • An internal review report that simulates the audit procedure
  • A mapping of your certificates and standards onto the thirteen measures

Frequently asked questions about the Act

Where there is one, the answers cite the article of the Act or the Regulation.

Who is an essential and who is an important entity under the Act?

Essential entities undergo an independent audit, important entities carry out a self assessment. The competent authority notifies you of your category, which follows from sector and size, with exceptions for the four critical healthcare activities and for state administration bodies.

What are the thirteen measures and where do they come from?

The thirteen measures from the Regulation break down into 99 sub-measures and 137 controls, across three levels of implementation: basic, intermediate and advanced. Every control calls for written evidence. They range from the security policy and risk management to cryptography, supply chain and physical protection.

What is the compliance deadline?

Twelve months from delivery of the categorisation notice, under Article 26(5) of the Act. The clock runs whether or not anyone has been named to lead the work, so organisations that wait for that appointment usually lose the first quarter.

What is the deadline for reporting a significant incident?

An early warning to the competent CSIRT within 24 hours, an initial incident notification within 72 hours, and a final report within 30 days. Where personal data are affected, a parallel notification goes to the data protection authority within 72 hours.

How does the Act relate to the AI Act?

Both call for the same kind of evidence: a register of systems, a risk assessment, oversight and records. If you keep the register of artificial intelligence systems apart from the asset register, you do the work twice. Cyber security is the foundation; AI governance builds on the same documentation.

We prepare you for the audit. We do not carry it out.

A formal audit is carried out by a provider holding the national security certificate, and for state administration bodies by ZSIS. Riskoria does not hold that certificate. A body that built the management system may not also assess it, and that separation protects you.

ZKS COPILOT

An assistant for the Cyber Security Act.

It explains categorisation, the thirteen measures, incident deadlines and self assessment, pointing to the article it relies on.

Try the Copilot

Not sure where you stand? Let us start with a conversation.

Thirty minutes, no obligation. You leave with a clear picture of what your organisation must do, and in what order.

Book a callINFO@RISKORIA.EU · +385 97 737 1345