NIS2 in Croatia — the earliest transposition, state-driven categorisation, and a two-year audit cycle.
Croatia was first: its Cybersecurity Act (NN 14/2024) entered into force on 15 February 2024 — before some member states had even drafted theirs — with the implementing Ordinance (NN 135/2024) following. The model is state-driven: rather than entities self-registering, the authorities categorise entities and notify them, a process that ran to February 2025, with notified entities given one year to reach compliance.
The regime's spine is a two-year assurance cycle: essential entities face an audit by a licensed auditor every two years; important entities a self-assessment every two years. The state register sits at authority level, with CERT.hr operating as the national CERT.
Who it applies to
Essential and important entities across the NIS2 sectors, categorised and notified by the authorities rather than self-registering — the categorisation round ran to February 2025 — with one year from notification to reach compliance. Essential entities undergo a licensed audit every two years; important entities file a self-assessment every two years. New entrants crossing thresholds are categorised as the authorities identify them.
The clock
Competent authority: State authorities (register) + CERT.hr as national CERT. Transposition: Cybersecurity Act (NN 14/2024).
| When | What happens |
|---|---|
| 15 Feb 2024 | Cybersecurity Act (NN 14/2024) enters into force — among the earliest transpositions |
| 2024 | Ordinance (NN 135/2024) adopted · categorisation framework set |
| Feb 2025 | Authority categorisation and notification round completes · one-year compliance clocks run |
| Every 2 years | Essential: licensed audit · Important: self-assessment |
The state categorises you — and the clock is two-yearly
Croatia inverts the usual flow: instead of entities self-identifying into the regime, the authorities categorise and notify. That places the triggering fact — the notification — outside the entity's control, which makes holding the notification date as a record the difference between a running compliance clock and a surprise. And once inside, the assurance cadence is fixed: a licensed audit every two years for essential entities, a self-assessment every two years for important ones. TruSecure holds the notification date, computes the one-year compliance window from it, and keeps the audit or self-assessment evidence current on a rolling basis — so the two-year cycle is a re-export, not a scramble.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Croatia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Hold your categorisation notice and its clock | Entity profile · notification date and one-year window as records |
| Reach compliance within one year of notification | Control library · continuously evidenced, gap list dated |
| Essential: licensed audit every two years | Audit trail · evidence assembled continuously, sealed exports |
| Important: self-assessment every two years | Risk register · assessment generated from live control state |
| Report incidents: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Categorisation notice
- received 11 Nov 2024 · essential, transport
- Compliance window
- closed · completed day 328 of 365
- Assurance cycle
- licensed audit · next due Mar 2027
- Controls evidenced
- 98/112 · 14 open, each with an owner and a date
- Export
- sealed · sha256:2e9b...7f3a
Where teams usually start
With a demo walked through by TruSecure — your categorisation notice and its clock on record, the controls you already operate credited against the Act, and the two-year audit or self-assessment cycle shown as a standing export. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Croatia by State authorities (register) + CERT.hr as national CERT. TruSecure determines applicability against Croatia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.