Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Knowledge base›CSA / NIS2
CSA / NIS2

13 measures, 99 sub-measures, 132 controls: the anatomy of Annex II

The Croatian Cybersecurity Regulation does not speak of ten NIS2 measures but of thirteen of its own. Beneath them sit 99 sub-measures, and behind those a catalogue of 132 controls with scoring thresholds. This is the map of the whole structure, measure by measure.

Daniel Bara, PhD10 February 20269 min read

The most common mistake in preparing for the Croatian Cybersecurity Act starts from the wrong list. NIS2 Article 21(2) enumerates ten groups of measures, so the figure ten keeps circulating in presentations and proposals. The Croatian Cybersecurity Regulation (OG 135/2024) breaks them down into thirteen measures, and those are what you will be assessed against.

The difference is not only in the counting. The Regulation sets the measures out in sub-measures, and the Croatian Information Systems Security Bureau (ZSIS) has published an evaluation framework alongside them with specific controls and scoring thresholds. If you are preparing evidence against the ten-point NIS2 list, some of that evidence will have nowhere to sit.

A three-level structure

A measure has a name and an objective. Within it sit sub-measures - concrete duties phrased as verbs (develop, document, implement, update). Each sub-measure carries a set of controls from the catalogue, and each control has a prescribed minimum score for the basic, medium and advanced levels.

All thirteen measures

The names are official, translated from Annex II of the Regulation and the ZSIS evaluation framework. The sub-measure counts are taken from that framework and add up to exactly 99.

MeasureName and what it asks for in practiceSub-measures
01Commitment and accountability of those responsible for implementing cyber risk management measures
The board approves the policy, appoints responsible people, provides resources and is reported to regularly. Without this the other measures have no owner.
11
02Management of software and hardware assets
An inventory of all assets, identification of critical assets, data classification and rules for disposal and reuse of equipment.
9
03Risk management
A documented risk assessment process on an all-hazards basis, the level and criticality of each risk, a named risk owner and a treatment plan.
8
04Security of human resources and digital identities
Pre-employment checks, contractual duties, access rights across the full lifecycle and separate accounts for administrators.
12
05Basic cyber hygiene practices
Patching, backups, endpoint protection, email and browser security, staff training and awareness.
11
06Securing network cyber security
Segmentation, perimeter protection, network traffic monitoring and secure configuration of network equipment.
5
07Physical and logical access control to network and information systems
Least privilege, multi-factor authentication, privileged access management and access records.
6
08Supply chain security
Minimum security requirements for suppliers, contractual clauses, third-party risk assessment and monitoring over time.
6
09Security in the development and maintenance of network and information systems
Security requirements in development, separated environments, change management and testing before go-live.
6
10Cryptography
Rules on the use of cryptography, protection of data in transit and at rest, key management and preparation for quantum-resistant cryptography.
6
11Incident handling
Detection, classification and escalation, a response plan, notification to the competent CSIRT within the prescribed deadlines and post-incident analysis.
6
12Business continuity and cyber crisis management
Business impact analysis, continuity and recovery plans, crisis management and regular exercising of the plans.
8
13Physical security
Protection of areas holding equipment, entry control, fire and water protection, and power and cabling security.
5
ΣTotal99

The controls per measure add up to more than 132 because individual controls are reused across measures. The control catalogue contains 132 unique identifiers, grouped into thirteen prefixes (POL, INV, RIZ, DID, EDU, UPR, NAD, RES, ORG, SKM, POD, SRZ, FIZ).

Where most of the work sits

Judging by sub-measure count alone, the weight is clear: measure 4 (security of human resources and digital identities) with twelve, and measures 1 and 5 with eleven each. That is not an accident. All three are organisational rather than technical.

The consequence is uncomfortable for teams that treat this as an IT project: most of the evidence base is not produced in the server room but in HR, in board meetings and in training records. A firewall is configured in a day. Evidence that the board approved the policy, received a report and allocated resources cannot be manufactured retrospectively.

Three levels of implementation

Each measure is assessed at one of three levels: basic, medium or advanced. The level is not freely chosen - it follows from the entity category and from the risk assessment. The same sub-measure at the advanced level demands a higher result on the same controls, and sometimes additional controls that do not apply at the basic level at all.

In the evaluation framework those conditional controls are marked with an asterisk. Sub-measure 10.6 is an example: it requires quantum-resistant cryptography proportionate to assessed risk. It is marked conditional at every level, which means your risk assessment can create an obligation you would otherwise have skipped on category alone.

What this looks like once it becomes a plan

Ninety-nine sub-measures sounds unmanageable until they are sorted on three criteria:

  • What you already have. An organisation with a working ISO 27001 system typically has substantial coverage of measures 2, 3, 7, 8 and 12. That gets mapped, not rewritten.
  • What has no owner. A sub-measure without a named owner will not get done, however simple it is.
  • What has the longest lead time. A policy takes a week to write. An annual board reporting cycle, a continuity plan exercise and a training record all need calendar time that cannot be compressed.

That last point explains why twelve months is not generous. Several measures are evidenced by records that only come into existence once a cycle has run.

A note on versions. The control catalogue and thresholds are published by ZSIS and revised through new versions of the guidance. Check which version is current before a formal self-assessment.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.