Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Knowledge base›Self-assessment
Self-assessment

How the self-assessment is actually scored: the Pi and T thresholds

You can satisfy every individual control and still fail the sub-measure. The evaluation framework has two thresholds, and the second one is the surprise. Here is how the formula works and what it means for planning.

Daniel Bara, PhD1 September 20266 min read

The self-assessment under the Croatian Cybersecurity Regulation is not a yes/no questionnaire. It is a scoring exercise with two thresholds that must be met simultaneously, and organisations that realise this late usually find they have been working towards the wrong target.

Two thresholds, not one

Every sub-measure has its own set of controls. For each control the framework prescribes a minimum score to pass, depending on the level of implementation. But that is not all.

The condition for passing a sub-measure

1. Every individual control must reach its minimum threshold (Oi ≥ Pi, for every control i).

2. The average score across all controls in the sub-measure must reach an additional threshold (∑Oi / n ≥ T).

Both conditions must hold. If the average does not pass, the sub-measure fails regardless of every control having passed individually.

An example from the framework: sub-measure 3.2, risk assessment over critical assets. At the basic level the controls carry thresholds of ≥3, ≥2, ≥2 and ≥2, with an additional average threshold of >2.5. An organisation that brings each control to exactly its minimum scores an average of 2.25 and fails the sub-measure, despite having formally satisfied every individual criterion.

Why the second threshold exists

The framework says so explicitly: the additional threshold acts as a final check on whether the controls are genuinely applied and integrated, rather than merely formally satisfied. The aim is to prevent a system in which every box is ticked while the measure does not work in practice.

The same logic goes one step further. If a measure is found not to be effective or not integrated into the risk management system, it can be assessed as unsatisfactory even where the controls formally pass. That room for judgement exists deliberately.

What this changes in planning

  • Do not aim at the minimum. Planning to "just about enough" on each individual control leads mathematically to failure on the average. Aim at the average threshold and work the controls back from there.
  • One weak control damages the sub-measure twice. It fails on its own and it drags the average down. The lowest-scoring controls are the most economical to fix.
  • The average is computed within a sub-measure, not within a measure. A strong result on one sub-measure does not compensate for a weak one elsewhere.
  • Scores are assigned against the control catalogue. Scoring by feel does not survive verification, because every score has to be defensible with evidence.

Levels change the thresholds, not the controls

Moving from the basic to the medium level generally does not bring a new list of controls but higher thresholds on the same ones. The typical pattern is a shift from ≥2 to ≥3, with the average threshold moving from 2.0 to 3.0. That matters, because an organisation preparing for the basic level and then recategorised does not have to build a new system - it has to deepen the one it has.

The exception is the controls marked with an asterisk, which apply conditionally depending on the risk assessment. Those can be triggered even at the basic level.

A practical check before the formal exercise

Before the self-assessment is submitted, it is worth running an internal review that simulates the process: score every control, compute the averages per sub-measure, and look at which sub-measures fail on the second threshold. The list is almost always shorter than expected, and it almost always contains sub-measures the team was confident were finished.

A note on versions. The formula and thresholds are published by ZSIS and revised through new versions of the guidance. Check which version is current before a formal self-assessment.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.