Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Knowledge base›CSA / NIS2
CSA / NIS2

Entity categorisation under the Croatian Cybersecurity Act, and what follows from it

You do not choose your category and you do not apply for it. It arrives by letter, and from that day a deadline runs. Here is who decides, on what basis, and what actually changes depending on which group you land in.

Daniel Bara, PhD20 January 20267 min read

The Croatian Cybersecurity Act (Official Gazette 14/2024), which transposes NIS2, splits those in scope into two groups: essential and important entities. The difference is not cosmetic. It determines the level at which you must implement the measures, who checks that you have, and what that check costs you.

Sector and size decide, subject to exceptions

The starting point is the annexes to the Act, which list the sectors in scope. Within a sector, the category is as a rule derived from the size of the entity against the criteria for medium and large undertakings. That is the rule. The exceptions are what matter.

The Act then lists groups where size is not a criterion at all. Essential regardless of size: qualified trust service providers, the national top-level domain registry and DNS service providers, e-invoice exchange intermediaries, entities designated as critical under the critical infrastructure legislation, state administration bodies and operators of the state information infrastructure. Important regardless of size: trust service providers not classified as essential, providers of public electronic communications networks and services not classified as essential, local and regional self-government units, and entities in the education system.

In addition, Article 11 allows any entity listed in the annexes to be categorised regardless of size where it is the sole provider of a service essential to maintaining critical societal or economic activities, where its disruption could significantly affect public safety, security or health, could cause systemic risk, or where it is significant because of its particular importance nationally, regionally or locally. That article is why a small institution can be an essential entity just as a large one is, and it is the most common source of surprise.

What this means in practice

Do not try to work out your own category and budget against it. A sectoral exception can change the whole scenario. Plan for the less favourable outcome until the written notice arrives.

What the category actually changes

Both groups implement the same 13 measures from Annex II of the Cybersecurity Regulation (OG 135/2024). What differs is the level of implementation and the method of verification.

Important entityEssential entity
MeasuresThe same 13 measuresThe same 13 measures
Level of implementationAs a rule lowerAs a rule higher
VerificationSelf-assessmentIndependent audit
Who verifiesThe entity itself, following the guidanceAn authorised external provider; for state bodies, the competent authority
Cost of verificationInternal effortExternal engagement

One point that is regularly missed: a self-assessment is also a formal procedure. It is not an internal opinion but a scoring exercise against a prescribed framework, with evidence that has to exist at the time of assessment. The difference from an audit is who holds the pen, not whether an evidence base is needed.

The clock starts with the notice, not with the Act

This is the most expensive misunderstanding in practice. The Act has been in force since 2024, but your deadline did not start then.

  • 30 days - the period within which the competent authority must notify you of the categorisation or a change to it.
  • 12 months - the compliance period, running from the delivery of that notice.
  • Up to two further years - the window within which conformity is verified, by independent audit or self-assessment depending on category.
  • 60 days to 6 months - the period the competent authority sets when a category changes, proportionate to the scope and complexity of the new duties.
Where the time goes

The first quarter is usually spent internally appointing someone to own the work. The deadline runs in the meantime. If the notice has arrived, the gap assessment can start before that appointment is formalised - you need the asset inventory and the risk register either way.

What to do in the first week after the notice

  1. Record the date of delivery. Not the date on the letter, the date of delivery. All twelve months are counted from it.
  2. Establish the level of implementation that applies to you and any sectoral duties that came with the categorisation.
  3. Appoint a responsible person and give them access to the board. Measure 1 of Annex II asks for exactly that, and it is scored.
  4. Build the asset inventory. Without it you cannot produce a risk assessment, and without a risk assessment almost no other measure passes.
  5. Check the overlaps. If you hold ISO 27001, are subject to DORA or have a working GDPR programme, part of the evidence base already exists. Map before you start writing new documents.

If you believe you have been miscategorised

Categorisation is based on the sector and size data the authority holds. If that data is wrong, or your activity has changed, that is a matter to raise with the competent authority - it is not a reason to let the deadline run unattended. Until it is resolved, the clock runs on the notice you received.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.