RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

The Cyber Security Act, the provisions people look for most often

Act NN 14/2024 transposes the NIS2 directive, while the measures are set by Regulation NN 135/2024. They are gathered here in one place, with article numbers.

What the Act is and where it comes from

The Act is the Croatian implementation of a European directive, and the measures themselves are set out in the Regulation that elaborates it.

The Cyber Security Act (ZKS), NN 14/2024, transposes into Croatian law the directive on measures for a high common level of cybersecurity, known as NIS2. The Act itself governs who is covered, who supervises and how large the fines are, but it does not list the measures in operational form. That is done by the Cyber Security Regulation, NN 135/2024, whose Annex II sets out thirteen measures broken into 99 sub-measures.

Those covered are categorised entities, essential and important. The category follows from the annexes to the Act and from size, with a series of exceptions that apply regardless of size. Categorisation is carried out by the competent authority, which notifies you within thirty days, and all your deadlines run from the day that notice is delivered.

The level of implementation, basic, medium or advanced, is set by the national risk assessment during categorisation, under Article 38 of the Regulation. It does not depend on whether you are an essential or an important entity, which is the distinction most often overlooked in practice.

Responsibility rests with the management body. Article 29 of the Act requires the persons responsible for managing the measures, that is the management body of the entity or the head of the authority, to approve the measures themselves and to control their implementation, and to acquire the knowledge and skills to do so. Article 26(4) adds that the obligation applies whether you run the systems yourself or through an external provider, so a contract does not lift it off the entity.

If you need a quick answer to a specific question with a reference to the article, that is what we built ZKS Copilot for. It is not a substitute for advice, but it shortens the path to the source.

Who is an essential and who an important entity

The category depends on the annex of the Act, on size, and for some entities on an assessment of importance.

GROUPCATEGORYNOTE
Annex I entities above the ceilings for medium-sized enterprisesEssentialThe ceiling is exceeded at 250 or more employees, or when both financial thresholds are passed: turnover above 50 million and assets above 43 million euros
Qualified trust service providers, the top-level domain registry, DNS providersEssentialRegardless of size, Article 9, indent 2
Annex II entities, medium and largeImportantEven large Annex II entities are important, not essential
Annex I entities that are medium-sizedImportantArticle 10, indent 2; the exception is providers of public electronic communications networks and services, which are essential even when medium-sized
State administration bodiesEssentialRegardless of size, Article 12(1)
Other state bodies and legal persons with public authorityEssentialRegardless of size, but subject to an assessment of importance for essential activities
Local and regional self-government unitsImportantRegardless of size, subject to an assessment of importance, Article 12(3)
Entities in the education systemImportantRegardless of size, subject to an assessment of particular importance, Article 13

An entity classified as both essential and important is treated as essential, under Article 16 of the Act, and therefore faces a mandatory audit rather than a self-assessment. Micro and small entities are in principle outside the Act, unless caught by provisions that apply regardless of size. In addition, an Annex I or II entity may be classified regardless of size under the special criteria of Article 11, for example if it is the sole provider of a service or if disruption would significantly affect public health. In healthcare that is done on a reasoned request from the body responsible for health, under Article 10 of the Regulation.

The deadlines in one place

Deadlines tied to categorisation run from delivery of the notice; those tied to an incident run from becoming aware.

OBLIGATIONDEADLINELEGAL BASIS
Notice of the completed categorisation30 days from categorisationAct, Art. 19(4)
Implementation of the Annex II measuresOne year from delivery of the noticeAct, Art. 26(5)
Deadline on a change of categoryFrom 60 days to six monthsAct, Art. 26(6) and (7)
Start of the duty to report significant incidents30 days from delivery of the noticeAct, Art. 37(4)
Early warning to the competent CSIRTWithout delay, no later than 24 hours from becoming awareRegulation, Art. 66
Initial incident notificationWithout delay, no later than 72 hours from becoming awareRegulation, Art. 67
Final incident report30 days from the initial notificationRegulation, Art. 70
Cyber security audit, essential entitiesAt least once every two yearsAct, Art. 34(1)
Self-assessment, important entitiesAt least once every two yearsAct, Art. 35(1)
Submission of the audit report to the authorityNo later than 8 days from receiptAct, Art. 34(5)
Submission of the declaration of conformity or action planNo later than 8 days from draftingAct, Art. 35(5)
Regular supervision of essential entitiesAt least once every three to five yearsAct, Art. 75(1)

The deadlines for the audit and for supervision start on the first working day after the deadline for implementing the measures expires, under Article 112 of the Act. Important entities are audited only when the competent authority asks for it, under Article 34(4). Where the audit was carried out at the authority request, the report goes out immediately on receipt, under Article 34(6). If an incident is still running when the final report falls due, a progress report is submitted instead.

What supervision looks like

Two things get mixed up regularly. You order and pay for the audit; expert supervision is carried out by the competent authority and is not your choice.

WHATWHO CARRIES IT OUTWHENLEGAL BASIS
Cyber security auditA certified auditor, and in state administration bodies the Information Systems Security BureauEssential entities at least once every two years, and sooner at the request of the competent authorityAct, art. 32 and 34
Self-assessmentThe entity itselfImportant entities at least once every two yearsAct, art. 35(1)
Audit on requestA certified auditorImportant entities, only when the competent authority asks for itAct, art. 34(4)
Regular expert supervisionThe competent authorityOver essential entities, at least once every three to five yearsAct, art. 75(1)
Extraordinary expert supervisionThe competent authorityBefore that deadline too, when the authority has information that duties are not being metAct, art. 75(2)

Supervision is carried out by the competent authority from Annex III to the Act, so for most sectors the central state body for cyber security, and for the public sector the central state body for information security. The Information Systems Security Bureau is not a supervisory authority; it is the auditor in state administration bodies and other state bodies, under article 32(3).

The clock does not start with the categorisation notice. The deadlines for the audit and for regular expert supervision run from the first working day after the deadline for implementing the measures expires, that is a year after the notice was served, under article 112 read with article 26(5).

In supervision you are required to cooperate and to grant access, under articles 77 to 79, and access specifically under article 78. That is not a formality: failure to cooperate and failure to grant access are offences in their own right, carrying the same range of fines as failing to implement the measures.

Findings are followed by corrective measures, under articles 82 and 83. Failing to act on them is a separate offence, so a finding left unresolved costs twice. When the fine is set, the circumstances in article 85 are taken into account.

What is assessed is the same in an audit and in supervision: implementation of the measures from Annex II to the Regulation. That is why a body of evidence arranged by measure and sub-measure serves both and is not built twice.

The details of the procedure are set out in articles 75 to 100 of the Act. What stands here is what we could confirm from the text of the Act; for how a particular procedure runs, the act of the competent authority governs, not this page.

Fines

The range is the same for every offence listed in the relevant article, and the higher of the two amounts applies.

WHORANGELEGAL BASIS
Essential entityFrom 10,000 to 10,000,000 euros, or from 0.5 to 2 per cent of total worldwide annual turnover, whichever is higherAct, Art. 101(1)
Important entityFrom 5,000 to 7,000,000 euros, or from 0.2 to 1.4 per cent of turnover, whichever is higherAct, Art. 102(1)
Responsible person in an essential entityFrom 1,000 to 6,000 eurosAct, Art. 101(2)
Responsible person in an important entityFrom 500 to 3,000 eurosAct, Art. 102(2)
Failure to submit required dataFrom 2,000 to 20,000 eurosAct, Art. 103(1)

The same range covers failures in implementing the measures, using certified products, management accountability, incident reporting, notifying service recipients, the audit and self-assessment, cooperation with the competent CSIRT and acting on corrective measures. When setting the fine, the circumstances in Article 85 of the Act are taken into account.

Frequently asked questions

Questions about the Act itself, not already answered above.

Does the Act apply to small companies?

In principle no, but there are exceptions that apply regardless of size: qualified trust service providers, the top-level domain registry and DNS providers, information intermediaries for electronic invoicing, critical entities, public sector bodies and the education system. Also important regardless of size are non-qualified trust service providers and providers of public electronic communications networks and services that are not essential, under Article 10, indents 3 and 4. In addition, the authority may classify you under the special criteria of Article 11, for example if you are the sole provider of a service.

Who supervises implementation?

It depends on the sector. For most sectors the authority competent for cyber security requirements is the central state authority for cyber security, and for the public sector the central state authority for information security. For banking and financial market infrastructure, Annex III names no body in the cyber security requirements column; it names the Croatian National Bank and the Croatian Financial Services Supervisory Agency as the bodies competent for sectoral legislation. A full breakdown by sector is on the sectors page.

Who carries out the audit?

Managed security service providers holding the national security certificate for auditing, or an equivalent European certificate, under Article 32(2) of the Act. For state administration bodies and other state bodies the auditor is the Information Systems Security Bureau (ZSIS).

Where is an incident reported?

To the CSIRT competent for your sector. For most sectors that is the national cyber security centre, and for banking, financial market infrastructure, the top-level domain registry, and research and education, the national CERT. A personal data breach is notified in parallel to the data protection authority within 72 hours.

How does the Act relate to the NIS2 directive?

The Act is the Croatian implementation of the directive. If you operate in several member states the obligations are comparable, but the competent authorities, reporting channels and detailed deadlines differ by country, so each is checked separately.

Does the obligation apply if an external provider runs the system?

It does. Article 26(4) of the Act states expressly that the obligation exists whether you run the systems yourself or through an external service provider. A contract does not transfer responsibility; it calls for security clauses.

Is there any obligation for entities that are not categorised?

There is no obligation, but there is a voluntary regime. In its part on voluntary mechanisms the Act provides for self-assessment and participation in the national threat detection system, which some entities use because their clients ask for it.

Where can a particular provision be checked quickly?

In the Official Gazette, because the source is always the legislation itself. To find your way faster we built ZKS Copilot, which cites the article with every answer so the claim can be verified at source.

Related pages

Individual parts of the Act are set out in full on their own pages.

Let us check which provisions actually apply to you.

Half an hour, no obligation. We go through your activity, size and categorisation notice and tell you what follows.

Book a callINFO@RISKORIA.EU · +385 97 737 1345