The most common mistake in preparing for the Croatian Cybersecurity Act starts from the wrong list. NIS2 Article 21(2) enumerates ten groups of measures, so the figure ten keeps circulating in presentations and proposals. The Croatian Cybersecurity Regulation (OG 135/2024) breaks them down into thirteen measures, and those are what you will be assessed against.
The difference is not only in the counting. The Regulation sets the measures out in sub-measures, and the Croatian Information Systems Security Bureau (ZSIS) has published an evaluation framework alongside them with specific controls and scoring thresholds. If you are preparing evidence against the ten-point NIS2 list, some of that evidence will have nowhere to sit.
A measure has a name and an objective. Within it sit sub-measures - concrete duties phrased as verbs (develop, document, implement, update). Each sub-measure carries a set of controls from the catalogue, and each control has a prescribed minimum score for the basic, medium and advanced levels.
All thirteen measures
The names are official, translated from Annex II of the Regulation and the ZSIS evaluation framework. The sub-measure counts are taken from that framework and add up to exactly 99.
| Measure | Name and what it asks for in practice | Sub-measures |
|---|---|---|
| 01 | Commitment and accountability of those responsible for implementing cyber risk management measures The board approves the policy, appoints responsible people, provides resources and is reported to regularly. Without this the other measures have no owner. | 11 |
| 02 | Management of software and hardware assets An inventory of all assets, identification of critical assets, data classification and rules for disposal and reuse of equipment. | 9 |
| 03 | Risk management A documented risk assessment process on an all-hazards basis, the level and criticality of each risk, a named risk owner and a treatment plan. | 8 |
| 04 | Security of human resources and digital identities Pre-employment checks, contractual duties, access rights across the full lifecycle and separate accounts for administrators. | 12 |
| 05 | Basic cyber hygiene practices Patching, backups, endpoint protection, email and browser security, staff training and awareness. | 11 |
| 06 | Securing network cyber security Segmentation, perimeter protection, network traffic monitoring and secure configuration of network equipment. | 5 |
| 07 | Physical and logical access control to network and information systems Least privilege, multi-factor authentication, privileged access management and access records. | 6 |
| 08 | Supply chain security Minimum security requirements for suppliers, contractual clauses, third-party risk assessment and monitoring over time. | 6 |
| 09 | Security in the development and maintenance of network and information systems Security requirements in development, separated environments, change management and testing before go-live. | 6 |
| 10 | Cryptography Rules on the use of cryptography, protection of data in transit and at rest, key management and preparation for quantum-resistant cryptography. | 6 |
| 11 | Incident handling Detection, classification and escalation, a response plan, notification to the competent CSIRT within the prescribed deadlines and post-incident analysis. | 6 |
| 12 | Business continuity and cyber crisis management Business impact analysis, continuity and recovery plans, crisis management and regular exercising of the plans. | 8 |
| 13 | Physical security Protection of areas holding equipment, entry control, fire and water protection, and power and cabling security. | 5 |
| Σ | Total | 99 |
The controls per measure add up to more than 132 because individual controls are reused across measures. The control catalogue contains 132 unique identifiers, grouped into thirteen prefixes (POL, INV, RIZ, DID, EDU, UPR, NAD, RES, ORG, SKM, POD, SRZ, FIZ).
Where most of the work sits
Judging by sub-measure count alone, the weight is clear: measure 4 (security of human resources and digital identities) with twelve, and measures 1 and 5 with eleven each. That is not an accident. All three are organisational rather than technical.
The consequence is uncomfortable for teams that treat this as an IT project: most of the evidence base is not produced in the server room but in HR, in board meetings and in training records. A firewall is configured in a day. Evidence that the board approved the policy, received a report and allocated resources cannot be manufactured retrospectively.
Three levels of implementation
Each measure is assessed at one of three levels: basic, medium or advanced. The level is not freely chosen - it follows from the entity category and from the risk assessment. The same sub-measure at the advanced level demands a higher result on the same controls, and sometimes additional controls that do not apply at the basic level at all.
In the evaluation framework those conditional controls are marked with an asterisk. Sub-measure 10.6 is an example: it requires quantum-resistant cryptography proportionate to assessed risk. It is marked conditional at every level, which means your risk assessment can create an obligation you would otherwise have skipped on category alone.
What this looks like once it becomes a plan
Ninety-nine sub-measures sounds unmanageable until they are sorted on three criteria:
- What you already have. An organisation with a working ISO 27001 system typically has substantial coverage of measures 2, 3, 7, 8 and 12. That gets mapped, not rewritten.
- What has no owner. A sub-measure without a named owner will not get done, however simple it is.
- What has the longest lead time. A policy takes a week to write. An annual board reporting cycle, a continuity plan exercise and a training record all need calendar time that cannot be compressed.
That last point explains why twelve months is not generous. Several measures are evidenced by records that only come into existence once a cycle has run.
A note on versions. The control catalogue and thresholds are published by ZSIS and revised through new versions of the guidance. Check which version is current before a formal self-assessment.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.