NIS2 in Croatia
What the Croatian transposition (ZKS) means for your subsidiary - scope, fines, mandatory measures, and how to get compliant bilingually.
In short
Croatia transposed NIS2 through its Cybersecurity Act (ZKS, Official Gazette NN 14/2024), with measures detailed in the Cybersecurity Regulation (NN 135/2024).
If your Croatian subsidiary operates in an Annex I or Annex II sector and meets the size thresholds, it is an essential or important entity — with mandatory risk-management measures (including MFA), incident reporting, management accountability, and fines up to 10 million EUR or 2% of worldwide turnover.
The competent authority categorises entities and notifies them — but the obligations do not wait for perfect clarity.
Is your Croatian entity in scope?
The Act divides sectors into two annexes.
Annex I (high criticality: energy, transport, banking and financial infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space) can make an entity essential; Annex II (postal, waste, chemicals, food, manufacturing of certain products, digital providers, research) makes it important.
Size matters in general (medium-sized and up), with notable exceptions where it does not. The competent authority performs the categorisation and notifies the entity.
Our Croatian-language self-check questionnaire walks through the exact thresholds: vi-di.me/zks-obveznik (your local team can complete it in minutes).
What must an obligated entity do?
Risk-management measures
Policies, incident handling, business continuity, supply-chain security, encryption - and explicitly multi-factor authentication (NIS2 Art. 21(2)(j)).
Incident reporting
24h early warning and 72h notification windows per the NIS2 framework and the Croatian Cybersecurity Regulation (NN 135/2024) - which requires prepared procedures.
Evidence & accountability
Management is accountable by law. Supervision looks for documented, implemented measures - local-language policies, training records, exported configurations.
The MFA measure, done properly
Because AiTM phishing kits routinely bypass SMS and app codes, the strongest and most auditable way to satisfy the MFA measure is phishing-resistant hardware keys — enforced via authentication strengths in Microsoft 365/Entra ID or Google Workspace. We cover local procurement, rollout and bilingual training: YubiKey in Croatia.
How high are the fines?
| Entity type | Fine range | Or % of worldwide turnover |
|---|---|---|
| Essential | 10,000 - 10,000,000 EUR | 0.5% - 2% (whichever is higher) |
| Important | 5,000 - 7,000,000 EUR | 0.2% - 1.4% (whichever is higher) |
Responsible individuals can additionally be fined personally; management carries explicit accountability.
Why is a group policy not enough by itself?
The Croatian entity is the obligated party under Croatian law. Supervision expects measures implemented and evidenced locally: Croatian-language policies and training records, incident reporting wired to the Croatian CSIRT, exported technical configurations, and local management sign-off.
We take a group security baseline and land it in the subsidiary — working in English with headquarters and in Croatian with the local team: email security (DMARC/SPF/DKIM), phishing-resistant MFA, backup verification, incident procedure and the audit-ready evidence folder.
What do foreign parent companies ask most?
Does NIS2 apply to our Croatian subsidiary?
First the sector, then the size. The subsidiary must operate in a sector listed in Annex I of the Act (high-criticality: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space) or Annex II (other critical: postal services, waste, chemicals, food, manufacturing of certain goods, digital providers, research, education). Some categories are in scope regardless of size. The competent authority performs the categorisation and notifies the entity within 30 days of it.
Which size thresholds put a Croatian company in scope?
You exceed the medium-entity ceiling with 250 or more employees, or by breaching both financial thresholds at once - over 50M EUR turnover and over 43M EUR balance-sheet total. Breaching only one of the two is not enough. Critically for group-owned companies, the thresholds apply only to an independent entity: if anyone who is not itself a small-business entity holds more than 25 % of the ownership or voting rights, size is measured together with the group. A twenty-person Croatian subsidiary of a large group therefore normally exceeds the ceiling regardless of its own headcount.
What are the penalties under the Croatian Cybersecurity Act?
For essential entities: fines from 10,000 up to 10,000,000 EUR or 0.5% to 2% of total worldwide annual turnover, whichever is higher (Article 101). For important entities: from 5,000 up to 7,000,000 EUR or 0.2% to 1.4% of turnover (Article 102). Responsible individuals within the entity can also be fined personally, and management carries explicit accountability for cybersecurity risk management.
What are the incident reporting deadlines?
The commonly cited 24-hour early warning and 72-hour incident notification come from the NIS2 framework and Croatia's implementing Cybersecurity Regulation (NN 135/2024), which details the reporting procedure. Practically: an obligated entity must be able to detect an incident, assess it and notify the competent CSIRT within those windows - which requires prepared procedures, not improvisation.
Is multi-factor authentication actually mandatory?
Yes - NIS2 Article 21(2)(j), transposed by the Croatian Act, explicitly lists multi-factor or continuous authentication solutions among the minimum risk-management measures. Because AiTM phishing kits routinely defeat SMS and app codes, phishing-resistant hardware keys are the strongest and most auditable way to satisfy the measure - see our YubiKey in Croatia page for local procurement and rollout.
Our headquarters already has a group security policy. Is that enough?
Usually not by itself. The Croatian entity is the obligated party under Croatian law: it needs measures implemented and evidenced locally (including Croatian-language training and documentation for supervision), incident reporting wired to the Croatian CSIRT, and management sign-off at the local level. A group policy is a good starting point that still has to be landed in the subsidiary - that is exactly the work we do, bilingually.
Need your Croatian subsidiary NIS2-ready?
Scoping call in English, delivery in Croatian and English. Fixed-scope packages for SME-sized entities.