Croatia transposed the NIS2 Directive (Directive (EU) 2022/2555) through the Zakon o kibernetičkoj sigurnosti (Cybersecurity Act), adopted by the Croatian Parliament on 26 January 2024, published as Narodne novine No. 14/2024, and in force from 15 February 2024 (Article 116, eighth day after publication).
The Act's Article 30 sets the risk-management measures every essential and important entity must take (risk-analysis and information-security policies, incident handling, business continuity, supply-chain security, secure development and vulnerability handling, measures-effectiveness review, basic cyber hygiene and training, cryptography, human-resources security and access control, and multi-factor or continuous authentication), and its Article 29 puts approval and oversight of those measures, plus a personal training duty, on the entity's own management body or, for a public entity, the heads of the relevant state administration or local self-government body.
The Act's Article 37 creates a general duty to notify the competent CSIRT of every significant incident and its Article 38 a duty to notify affected service recipients, but a genuine structural departure from the pattern this session confirmed across roughly a dozen other Member States is that neither article states the graduated notification clock itself: Article 44 delegates the type, content and deadlines of every notification under Articles 37 to 40 to an implementing regulation.
That regulation, the Uredba o kibernetičkoj sigurnosti (Narodne novine No. 135/2024, adopted by the Government on 21 November 2024 and in force from 30 November 2024 for the articles documented here), is what actually sets the 24-hour early warning, 72-hour initial notification (24 hours for a trust service provider), on-request interim report, and 30-day final report clock in its Articles 64 to 71, and a parallel 72-hour clock for notifying service recipients in its Article 85.
A second departure from the confirmed pattern sits in enforcement: Chapter Nine of the Act calls an Article 29, 30, 37 or 38 failure a prekršaj (misdemeanor) rather than an administrative offense the regulator sanctions directly, and Article 104 requires the competent authority to report a suspected failure to the competent state attorney, who prosecutes it as a misdemeanor before the misdemeanor court; every other Member State this session has read imposes its NIS2 fine as a direct administrative sanction.
The fine bands themselves are also expressed as two-sided ranges rather than a single ceiling: Article 101 sets an essential entity's fine at EUR 10,000 to EUR 10,000,000 or 0.5 percent to 2 percent of worldwide annual turnover, whichever amount is higher, and Article 102 sets an important entity's fine at EUR 5,000 to EUR 7,000,000 or 0.2 percent to 1.4 percent, with a further personal fine on a responsible individual under Article 29 of EUR 1,000 to 6,000 (essential entity) or EUR 500 to 3,000 (important entity).
Annex II (Prilog II, Other Critical Sectors) lists 'providers of digital services' at item 21 without a size floor of its own, and the Act's own definitions clause names a provider of an online marketplace, an online search engine, or a social networking services platform among the digital service providers it reaches; Article 10 applies the general medium-enterprise-or-larger threshold to Annex II entities to categorize them as important entities.
The wider sector classes Annexes I and II also name (energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing, research, education, and others) are recorded here as law the lint does not yet reach rather than flagged on a guess, since no activity in this vocabulary expresses that designation.
No Croatian instrument found here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and not restated here.
No general reasonable-security or information-security-programme statute with no sector gate was found; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Croatian Act on the Implementation of the GDPR's own breach-notification duties to AZOP, both of which sit in this jurisdiction's privacy row rather than here.