Skip to main content
NIS2 · CROATIA

NIS2 in Croatia — the earliest transposition, state-driven categorisation, and a two-year audit cycle.

Croatia was first: its Cybersecurity Act (NN 14/2024) entered into force on 15 February 2024 — before some member states had even drafted theirs — with the implementing Ordinance (NN 135/2024) following. The model is state-driven: rather than entities self-registering, the authorities categorise entities and notify them, a process that ran to February 2025, with notified entities given one year to reach compliance.

The regime's spine is a two-year assurance cycle: essential entities face an audit by a licensed auditor every two years; important entities a self-assessment every two years. The state register sits at authority level, with CERT.hr operating as the national CERT.

Who it applies to

Essential and important entities across the NIS2 sectors, categorised and notified by the authorities rather than self-registering — the categorisation round ran to February 2025 — with one year from notification to reach compliance. Essential entities undergo a licensed audit every two years; important entities file a self-assessment every two years. New entrants crossing thresholds are categorised as the authorities identify them.

The clock

Competent authority: State authorities (register) + CERT.hr as national CERT. Transposition: Cybersecurity Act (NN 14/2024).

NIS2 in Croatia · timeline
WhenWhat happens
15 Feb 2024Cybersecurity Act (NN 14/2024) enters into force — among the earliest transpositions
2024Ordinance (NN 135/2024) adopted · categorisation framework set
Feb 2025Authority categorisation and notification round completes · one-year compliance clocks run
Every 2 yearsEssential: licensed audit · Important: self-assessment

The state categorises you — and the clock is two-yearly

Croatia inverts the usual flow: instead of entities self-identifying into the regime, the authorities categorise and notify. That places the triggering fact — the notification — outside the entity's control, which makes holding the notification date as a record the difference between a running compliance clock and a surprise. And once inside, the assurance cadence is fixed: a licensed audit every two years for essential entities, a self-assessment every two years for important ones. TruSecure holds the notification date, computes the one-year compliance window from it, and keeps the audit or self-assessment evidence current on a rolling basis — so the two-year cycle is a re-export, not a scramble.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Croatia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Croatia requirements · how TruSecure answers them
What the law asksWhere it is answered
Hold your categorisation notice and its clockEntity profile · notification date and one-year window as records
Reach compliance within one year of notificationControl library · continuously evidenced, gap list dated
Essential: licensed audit every two yearsAudit trail · evidence assembled continuously, sealed exports
Important: self-assessment every two yearsRisk register · assessment generated from live control state
Report incidents: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Croatia NIS2 readiness file · excerptSample data
Categorisation notice
received 11 Nov 2024 · essential, transport
Compliance window
closed · completed day 328 of 365
Assurance cycle
licensed audit · next due Mar 2027
Controls evidenced
98/112 · 14 open, each with an owner and a date
Export
sealed · sha256:2e9b...7f3a

Where teams usually start

With a demo walked through by TruSecure — your categorisation notice and its clock on record, the controls you already operate credited against the Act, and the two-year audit or self-assessment cycle shown as a standing export. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Croatia by State authorities (register) + CERT.hr as national CERT. TruSecure determines applicability against Croatia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Was Croatia one of the first countries to transpose NIS2?
Yes — Croatia's Cybersecurity Act (NN 14/2024) entered into force on 15 February 2024, among the earliest transpositions anywhere in the Union.