RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

The Act is the same for everyone. The route to compliance is not.

Every sector has its own competent authority, its own CSIRT and its own typical findings.

Sectors and categories

The areas we cover

The sector sets the authority, the size sets the category

Three things get mixed up: the sector, the entity category and the level of measures. They are three different things, set in three different ways.

The sector follows from the activity and from the annexes to the Act. Annex I lists the sectors of high criticality, among them energy, transport, banking, healthcare, water, digital infrastructure, ICT service management, the public sector and space. Annex II lists the other critical sectors, postal services, waste management, manufacturing, food, research and the education system for instance.

The category, essential or important, follows from the annex and the size, with exceptions that apply regardless of size. Essential are Annex I entities above the ceilings for medium-sized enterprises; important are medium-sized Annex I entities and medium and large Annex II entities. The exception is providers of public electronic communications networks and services, which are essential even when medium-sized. An entity classified as both is treated as essential, under Article 16 of the Act.

The level of measures, basic, medium or advanced, follows from neither the sector nor the category. It is set by the national risk assessment during categorisation, under Article 38 of the Regulation. An essential entity at low risk may therefore sit at the basic level, and an important entity at high risk at the advanced one.

What the sector does determine is who supervises you and where you report an incident. For each sector, Annex III of the Act names the authority competent for cyber security requirements, the body competent for sectoral legislation, and the competent CSIRT.

Competent authorities and CSIRTs by sector

Under Annex III of the Act. A dash means the Annex names no body in that column for that sector.

Each sector page names the competent authority, the competent CSIRT, who from the sector falls in scope and where the work usually gets stuck. Open your own sector from the grid at the top of this page.

SECTORCOMPETENT AUTHORITYSECTORAL LEGISLATIONCSIRT
EnergyCentral state authority for cyber securityNCSC-HR
Transport: rail, water, roadCentral state authority for cyber securityNCSC-HR
Transport: airCroatian Civil Aviation AgencyNCSC-HR
BankingCroatian National BankNational CERT
Financial market infrastructureCroatian Financial Services Supervisory AgencyNational CERT
HealthcareCentral state authority for cyber securityNCSC-HR
Drinking water and waste waterCentral state authority for cyber securityNCSC-HR
Digital infrastructure: public electronic communicationsCroatian Regulatory Authority for Network IndustriesNCSC-HR
Digital infrastructure: DNS, cloud, data centresCentral state authority for cyber securityNCSC-HR
Digital infrastructure: trust servicesBody responsible for digital society developmentNCSC-HR
Top-level domain name registryBody responsible for science and educationNational CERT
ICT service managementCentral state authority for cyber securityNCSC-HR
Public sectorCentral state authority for information securityNCSC-HR
SpaceCentral state authority for cyber securityNCSC-HR
Research and the education systemBody responsible for science and educationNational CERT
Other Annex II sectorsCentral state authority for cyber securityNCSC-HR

The Information Systems Security Bureau is neither a supervisory authority under the Act nor a CSIRT for any sector. It is the central state authority for the technical areas of information security; it certifies managed security service providers and audits state administration bodies and other state bodies, under Article 32(3) of the Act.

Frequently asked questions

The questions we are asked most often before we start.

How do we know which sector we are in?

By the activity listed in the annexes to the Act, not by the activity code in the companies register. Where the line is unclear, what counts is which service is essential for users. The final word rests with the competent authority, which notifies you of the categorisation within thirty days.

Can we be in two sectors?

You can, and the stricter category then applies. An entity classified as both essential and important is treated as essential, under Article 16 of the Act, and therefore faces a mandatory audit rather than a self-assessment.

Do the measures differ by sector?

There are thirteen measures and they apply to every categorised entity. What differs is the level of implementation, set by the national risk assessment, and who the competent authority and CSIRT are. The exception is digital infrastructure, for which Annex III of the Regulation sets an extended set of physical security measures.

Which CSIRT is ours?

For most sectors the national cyber security centre. For banking, financial market infrastructure, the top-level domain name registry, and research and the education system, it is the national CERT.

What if nobody has notified us of a categorisation?

The notice is delivered by the competent authority within thirty days of the categorisation being carried out or the list being updated, under Article 19(4) of the Act. Until it arrives, the deadlines do not run for you, but that is no reason not to prepare, because the one-year clock starts on delivery.

Do sectoral rules apply alongside the Act?

They do. In finance the Act sits alongside the digital operational resilience regulation, in healthcare alongside health data legislation, and in energy and transport alongside critical infrastructure rules. The first task is to separate what falls under which, so the same record is not written twice.

Does the category change over time?

It does, because the list of entities is updated. On a change of category the authority sets a compliance deadline in the notice, which can be no shorter than sixty days and no longer than six months, under Article 26(6) and (7) of the Act.

Are micro and small entities in scope?

In principle no, but there are exceptions that apply regardless of size: qualified trust service providers, the TLD registry and DNS providers, information intermediaries for electronic invoicing, critical entities, the public sector and the education system. Also important regardless of size are non-qualified trust service providers and providers of public electronic communications networks and services that are not essential. In addition, the authority may classify an entity under the special criteria of Article 11.

Where to go next

Whatever the sector, the work is the same: measures, evidence and deadlines.

Not sure which category you fall into?

Half an hour, no obligation. We go through your activity and size and tell you what follows from it.

Book a callINFO@RISKORIA.EU · +385 97 737 1345