We know what the regulator asks for and what proves it. We work with essential and important entities on the Croatian Cybersecurity Act, on data protection and on ISO standards - and we tell you who does what, in what order, and which piece of evidence stands behind each measure.
Six instruments and two standards that keep overlapping in practice: the same asset inventory, the same risk register, the same records.
More than two decades at the intersection of information security, business processes and regulatory requirements.
Adventure Spirit Consulting grew out of a simple proposition: organisations deserve cybersecurity and risk management expertise fitted to real operations, not to generic templates. We work with clients who know what they want, and we know what they need.
We run projects one at a time, without unnecessary exposure. What shows are the results: information security management systems in operation, business continuity plans that have actually been exercised, data protection processes that hold, and organisations that walk into certification audits with confidence. Our experience spans banking, insurance, energy, healthcare, the food industry and the public sector - everywhere data and operational resilience are a question of survival.
Principal consultant Daniel Bara, PhD, brings more than 20 years of work in information security, a doctorate in business intelligence, an MBA, the PMP and CIPP/E certifications and experience as an external evaluator on more than 300 EU-funded projects. He has lectured at RIT Croatia since 2017, with guest lectures at ZSEM, VERN and Libertas.
Nine service lines, one evidence base. Where the requirements overlap, the documentation is written once.
Entity category is determined by the sector listed in the annexes to the Act and by size, subject to a number of exceptions where size is not the criterion at all.
Not advisory alone. We also run our own GRC platform that digitises risk management, compliance and security processes. Your team works in a system we built out of real implementations.
A structured approach that delivers - from the first assessment through to certification and continuous monitoring.
We have worked with organisations across financial services, insurance, energy, healthcare, the food industry, IT and sport - implementing ISMS, BCMS, GDPR, DORA, NIS2 and ISO certifications.
Articles on the Croatian Cybersecurity Act, ISO standards and risk management. Every claim carries the article of the law or standard behind it, where one exists.
Answers carry the article of the law or standard behind them, where one exists.
The category is determined by sector and by the size of the entity, subject to exceptions. Essential entities are subject to an independent cybersecurity audit, while important entities carry out a self-assessment. You are notified of the categorisation in writing by the competent authority. Size is not the criterion for state administration bodies and operators of the state information infrastructure (essential), for local and regional self-government and the education system (important), nor for trust service providers, DNS service providers and the national domain registry. In addition, Article 11 allows any entity to be categorised regardless of size if it is the sole provider of an essential service or if its disruption would significantly affect public safety, security or health.
Cybersecurity Act, OG 14/2024The Croatian Cybersecurity Regulation breaks the statutory duties down into 13 cyber risk management measures, set out in 99 sub-measures across three levels of implementation: basic, medium and advanced. The level that applies to you depends on your entity category and on your risk assessment. The scope runs from security policy and risk management through to cryptography, supply chain security and physical protection. Every control requires written evidence.
Cybersecurity Regulation, OG 135/2024, Annex IIA twelve-month period runs from the delivery of the categorisation notice, not from the date the Act entered into force. The competent authority must deliver that notice within 30 days of the categorisation. After the compliance period ends, conformity is verified - by independent audit for essential entities, by self-assessment for important ones. In practice organisations lose the first quarter waiting for an internal owner to be appointed, so we recommend starting the gap assessment as soon as the notice arrives.
Cybersecurity Act, OG 14/2024, Art. 26An early warning to the competent CSIRT within 24 hours of becoming aware, an incident notification within 72 hours and a final report within 30 days. If the incident also involves a personal data breach, a parallel notification to the Croatian data protection authority runs within 72 hours under Article 33 GDPR. The deadlines do not add up - they run in parallel, so the reporting process has to be prepared in advance rather than improvised during the incident.
Cybersecurity Act, OG 14/2024 · GDPR, Art. 33For the financial sector DORA is the more specific regime governing ICT risk management, resilience testing and oversight of ICT service providers. Entities subject to DORA do not thereby cease to be subject to other rules. The good news is that the evidence base overlaps heavily: the same asset register, the same risk register, the same register of third-party contracts and the same incident records. You do the work once and report it in several directions.
DORA, EU 2022/2554Not automatically, but a large part of the work is already done. ISO/IEC 27001:2022 covers a substantial share of the 13 measures - security policy, risk management, asset management, access control, supply chain security and business continuity. What ISO does not cover are the specifics of the Act: entity categorisation, the deadlines and format for reporting incidents to the competent CSIRT, and the content of the self-assessment. We therefore map your existing controls onto the measures and only fill the gap, instead of building a second set of documentation in parallel.
ISO/IEC 27001:2022, Annex ATwo to three weeks for a mid-sized organisation. The result is a scored assessment against every measure and control, a list of the evidence that is missing, a risk register and a compliance roadmap with priorities, owners and resource estimates. Everything is recorded in our GRC platform straight away, so you track progress continuously and with an audit trail rather than once a year in a spreadsheet.
We perform internal audits of management systems, compliance reviews and a documentation review that simulates the audit process. We do not perform ISO certification - by definition that is carried out by an accredited certification body, and whoever built a system may not certify it. The independent cybersecurity audit of essential entities under the Act is carried out by a provider holding the prescribed authorisation, and for state administration bodies by the competent authority.
We do perform internal audits of management systems, compliance reviews against the Croatian Cybersecurity Act and data protection law, and a documentation review that simulates the audit process before an external auditor arrives. We also act as external DPO and external CISO.
We do not perform ISO certification - by definition that is carried out by an accredited certification body, and nobody who built a system may also certify it. That separation is not a formality but protection for you: what we tell you is ready is ready for someone who has no interest in it being so.
Need a compliance assessment, an ISO implementation, DORA or NIS2 preparation, or a demo of the GRC platform? Write to us - we reply within 24 hours.