Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Services›CSA / NIS2 compliance
Services

CSA / NIS2 compliance

We deliver full implementation of cyber security for essential and important entities under the Croatian Cybersecurity Act. We cover everything from establishing your category and competent authority to setting up incident notification to the competent CSIRT.

Croatian Cybersecurity Act · EU NIS2 Directive

How we work

01Gap assessment
Scoring against each of the 13 measures of Annex II of the Regulation (OG 135/2024), by sub-measure and control, with a list of the evidence that is missing.
02Categorisation and competence
Establishing your status (essential or important entity), the competent authority, the level of implementation and the deadlines that follow.
03Implementation of the 13 measures
Risk management, supply chain security, MFA, encryption, incident handling, business continuity, training, cryptography, physical security and access management.
04Self-assessment and audit preparation
Self-assessment for important entities, or an internal review simulating the audit process for essential entities, with management review.
05Incident management
Establishing the notification process to the competent CSIRT: early warning within 24 hours, incident notification within 72 hours, final report within 30 days.
06Continuous monitoring
Integration into the GRC platform to track measure status, incidents and deadlines in real time.

What you get

Gap assessment report
Cyber security policy
Remediation plan
Measure register
Incident notification process
GRC platform setup

Measures of Annex II this service covers

01 Commitment and accountability of those responsible for implementing cyber risk management measures 02 Management of software and hardware assets 03 Risk management 04 Security of human resources and digital identities 05 Basic cyber hygiene practices 06 Securing network cyber security 07 Physical and logical access control to network and information systems 08 Supply chain security 09 Security in the development and maintenance of network and information systems 10 Cryptography 11 Incident handling 12 Business continuity and cyber crisis management 13 Physical security

Sectors where it is most in demand

Check for yourself before we talk

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.