This is an informative maturity assessment, not a formal self-assessment. The formal self-assessment follows the ZSIS scoring framework, where each of the 13 measures is broken into 99 sub-measures and a catalogue of 132 controls, with a threshold per control and an additional average threshold per sub-measure. This tool gives one score per measure and serves for rough orientation.
Readiness check against the 13 measures
Thirteen questions, one per measure of Annex II of the Croatian Cybersecurity Regulation. Not a substitute for the formal self-assessment against the ZSIS scoring framework, but it shows where you stand and what comes first.
For each measure choose the statement that best describes the actual state, not the intended one.
Commitment and accountability of those responsible for implementing cyber risk management measures · The board approves, appoints, provides resources and reviews. Without that the other measures have no owner.
Management of software and hardware assets · The inventory is a precondition for risk assessment, monitoring and almost every other measure.
Risk management · The Regulation requires an all-hazards approach, not just information threats.
Security of human resources and digital identities · From hiring and contractual duties through to revoking rights on departure, with separate administrator accounts.
Basic cyber hygiene practices · The measure with the most sub-measures after identity management, and the one that reduces real risk most.
Securing network cyber security · Segmentation is the highest-return control because it limits reach without touching individual systems.
Physical and logical access control to network and information systems · Particularly on remote access, email and administrator accounts.
Supply chain security · Contractual clauses, questionnaires, assessment and monitoring over time.
Security in the development and maintenance of network and information systems · Separated environments, testing before go-live, secure coding rules that also apply to acquired software.
Cryptography · The Regulation also asks you to consider quantum-resistant cryptography proportionate to assessed risk.
Incident handling · The deadlines are 24 hours, 72 hours and 30 days, running from awareness. The process must exist before the incident.
Business continuity and cyber crisis management · A plan that has never been exercised documents intent, not capability.
Physical security · A standalone measure with its own sub-measures, not part of a wider control set.
The tool runs entirely in your browser. Your answers do not reach our server.
Your readiness snapshot
Readiness by measure
One block is one maturity level. Grey columns are measures below the readiness threshold. The threshold is our internal indicator, not a statutory one - the statutory thresholds are set by the ZSIS framework per sub-measure and level.
Measures below the threshold
Detailed report by email
We send you your result with per-measure recommendations, and a short note on what we would tackle first in your position. You can also print or save the report as PDF right now with the button above.
We send only the result of this assessment and a response to it. You are not added to a mailing list and your address is not shared with third parties.
This is an extract from our GRC platform
In the platform the same assessment runs across all 99 sub-measures and 132 controls, with evidence, owners, deadlines and an audit trail - so you track progress continuously rather than once a year.