Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance
Zakon o kibernetičkoj sigurnosti, Narodne novine, broj 14/2024, čl. 29. i 30.
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 15 February 2024.
A sector security regimes rule binding public and private bodies.
As of 16 September 2026.
What it requires
- This binds you where you are an essential or important entity designated under the Cybersecurity Act, whose Annex II names providers of digital services among the other critical sectors it reaches and whose definitions clause names a provider of an online marketplace, an online search engine, or a social networking services platform expressly; you become an important entity at the general medium-enterprise-or-larger size threshold Article 10 applies to Annex II entities. The wider sector classes the Act also reaches (energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing, research, education and others) are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
- Take risk-management measures sized to your exposure, covering at minimum: risk-analysis and information-system-security policies, incident-handling procedures (monitoring, logging and reporting), business continuity including backup management and disaster recovery, supply-chain security accounting for your direct suppliers' and service providers' vulnerabilities, security in the acquisition, development and maintenance of your systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of your own measures, basic cyber-hygiene practices and training, cryptography and encryption policies, human-resources security and access control including asset inventories, and, where appropriate, multi-factor or continuous authentication and secured communications.
- Have the members of your management body, or, if you are a public entity, the heads of your state administration or local self-government body, approve these measures and control their implementation, and have them attend, and make available to your staff, appropriate cybersecurity training covering risk-management issues and their effect on your services.
- Expect a fine of EUR 10,000 to EUR 10,000,000 or 0.5 percent to 2 percent of your undertaking's worldwide annual turnover for the preceding financial year, whichever amount is higher, if you are an essential entity that fails these duties; EUR 5,000 to EUR 7,000,000 or 0.2 percent to 1.4 percent if you are an important entity. A responsible individual under this duty faces a personal fine of EUR 1,000 to 6,000 at an essential entity or EUR 500 to 3,000 at an important entity. The competent authority does not impose this fine itself: it reports a suspected failure to the competent state attorney, who prosecutes it as a misdemeanor before the misdemeanor court.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Chapter Nine of the Act (Dio deveti, Prekršajne odredbe) makes an Article 29 or 30 failure a prekrsaj (misdemeanor) rather than a kazneno djelo (criminal offense) under the Kazneni zakon, so this is not criminal exposure in the Croatian sense. It is nonetheless a state-prosecuted proceeding rather than a direct administrative sanction: Article 104 requires the competent authority to file a report with the competent state attorney (nadležni državni odvjetnik), who submits a prosecution proposal (optuzni prijedlog) to the misdemeanor court, a mechanism this session has not found in any other Member State's NIS2 transposition read so far.
Penalty structure
Article 101(1) sets an essential entity's fine at EUR 10,000 to EUR 10,000,000, or 0.5 percent to 2 percent of the entity's worldwide annual turnover for the preceding financial year, whichever amount is higher; this field states only the essential-entity fixed-cap and turnover-cap ends of that range. Article 102(1) sets an important entity's fine at EUR 5,000 to EUR 7,000,000, or 0.2 percent to 1.4 percent, whichever is higher, not separately structured here since this field holds one tier. Article 101(2) and Article 102(2) each add a personal fine on the individual responsible under Article 29: EUR 1,000 to 6,000 for an essential entity's responsible person, EUR 500 to 3,000 for an important entity's. Article 103 separately fines a failure to submit categorization or registry data, EUR 2,000 to 20,000 for the entity and EUR 200 to 1,000 for its responsible person, not represented in this field. Unlike the administrative-sanction mechanisms this session confirmed in other Member States, none of these fines is imposed by the competent authority directly: Article 104 routes a suspected violation to the competent state attorney, who prosecutes it as a misdemeanor before the misdemeanor court.
- Rule
- Higher of
- As of
- 16 September 2026
- Minimum
- 10,000
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The central state body for cybersecurity (Središnje državno tijelo za kibernetičku sigurnost) designated per sector in Prilog III (Annex III) of the Cybersecurity Act as the competent authority for cybersecurity requirements; for the digital-service-provider sector Annex III names the National Cybersecurity Centre (Nacionalni centar za kibernetičku sigurnost) as the competent CSIRT. A suspected failure is referred to the competent state attorney (Article 104), who prosecutes it as a misdemeanor before the misdemeanor court.
Settledness
- As of
- 16 September 2026
- Open questions
- The Act and the Regulation, as read in this session, name the central state body for cybersecurity and the National Cybersecurity Centre only by function, never by an institutional name. Is the central state body for cybersecurity the Sigurnosno-obavjestajna agencija (SOA), as independent commentary suggests, or a separate body?
- Article 15 sets out how the medium-enterprise threshold is applied by reference to the small-business incentive law's own headcount and turnover figures. What are the exact headcount and turnover figures that cross-referenced law sets for a digital service provider to clear the medium-enterprise threshold?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 30 of the Cybersecurity Act requires every essential and important entity to take risk-management measures covering, at minimum, risk-analysis and information-system-security policies, incident-handling procedures including monitoring, logging and reporting, business continuity such as backup management and disaster recovery and cybersecurity-crisis management, supply-chain security including the vulnerabilities and security practices of direct suppliers and service providers, security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of the entity's own risk-management measures, basic cyber-hygiene practices and cybersecurity training, cryptography and, where appropriate, encryption policies, human-resources security and access-control policies and asset management including regular inventory updates, and, where appropriate, multi-factor or continuous authentication, secured voice, video and text communications, and secure emergency communication systems.
Article 29 makes the members of an essential or important entity's management body, or the heads of the relevant state administration body, other state body, or local and regional self-government executive body for a public entity, responsible for implementing these measures: they must approve the risk-management measures the entity applies and control their implementation, and they must themselves attend appropriate training on risk-management issues and its effect on the entity's services, and make the same training available to the entity's staff.
Both articles transpose NIS2 Articles 21 and 20 respectively. Annex II (Prilog II, Other Critical Sectors) lists 'providers of digital services' at item 21. The Act's own definitions clause names a provider of an online marketplace, an online search engine, or a social networking services platform among the digital service providers it reaches.
When LexLint raises it
operates_social_platform
Read the law
Zakon o kibernetičkoj sigurnosti
adopted by the Croatian Parliament on 26 January 2024, published in Narodne novine No. 14/2024, in force from 15 February 2024, official gazette narodne-novine.nn.hr