Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations
Zakon o kibernetičkoj sigurnosti Narodne novine, broj 14/2024, čl. 37.-44.; Uredba o kibernetičkoj sigurnosti, Narodne novine, broj 135/2024, čl. 64.-71. i 85.
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 30 November 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 16 September 2026.
What it requires
- This binds you where you are an essential or important entity designated under the Cybersecurity Act, whose Annex II names providers of digital services among the other critical sectors it reaches and whose definitions clause names a provider of an online marketplace, an online search engine, or a social networking services platform expressly; the wider sector classes it also reaches are not separately raised here, for the reason given on this jurisdiction's companion risk-management-and-governance row.
- Notify the competent CSIRT of every significant incident on this clock, set by the Cybersecurity Regulation rather than the Act itself: an early warning without delay and no later than 24 hours after becoming aware of it (24 hours also for a trust service provider's initial notification), an initial notification no later than 72 hours otherwise, an interim report if the CSIRT requests one, and a final report no later than 30 days after your initial notification, or, if the incident is still unresolved at that point, a progress report instead, repeated every 30 days once the incident has run past 60 days, followed by a final report within 30 days of your last progress report.
- Notify the recipients of your service, without delay and no later than 72 hours after you become aware of a significant incident likely to affect them, in a clear and easily verifiable way, and separately notify them of a serious cyber threat and of any protective measures or remedies they can take.
- If you are newly categorized as an essential or important entity, you have 30 days from the date you receive your Article 19(1) categorization notice before these notification duties bind you.
- Same fine tiers and misdemeanor-prosecution mechanism as this jurisdiction's companion risk-management-and-governance row: EUR 10,000 to EUR 10,000,000 or 0.5 to 2 percent of worldwide turnover for an essential entity, EUR 5,000 to EUR 7,000,000 or 0.2 to 1.4 percent for an important entity, whichever amount is higher, referred to the state attorney for misdemeanor prosecution rather than imposed directly by the competent authority.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Chapter Nine of the Act makes an Article 37 or 38 reporting failure a prekrsaj (misdemeanor) rather than a kazneno djelo (criminal offense) under the Kazneni zakon. As with the companion risk-management duty, the competent authority does not impose this fine itself: Article 104 requires it to report a suspected failure to the competent state attorney, who prosecutes it as a misdemeanor before the misdemeanor court.
Penalty structure
Article 101(1) sets an essential entity's fine for a reporting failure at EUR 10,000 to EUR 10,000,000, or 0.5 percent to 2 percent of worldwide annual turnover for the preceding financial year, whichever amount is higher; this is the same penalty provision that governs the companion risk-management-and-governance row. Article 102(1) sets an important entity's fine at EUR 5,000 to EUR 7,000,000, or 0.2 percent to 1.4 percent, whichever is higher, not separately structured here since this field holds one tier. As with the companion row, none of these fines is imposed by the competent authority directly: Article 104 routes a suspected violation to the competent state attorney, who prosecutes it as a misdemeanor before the misdemeanor court.
- Rule
- Higher of
- As of
- 16 September 2026
- Minimum
- 10,000
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The central state body for cybersecurity (Središnje državno tijelo za kibernetičku sigurnost) as the competent authority, with notifications received by the competent CSIRT Annex III names per sector (the National Cybersecurity Centre for a digital service provider). A suspected reporting failure is referred to the competent state attorney (Article 104), who prosecutes it as a misdemeanor before the misdemeanor court.
Settledness
- As of
- 16 September 2026
- Open questions
- Regulation Article 116 exempts only its own Articles 104 and 105 from the standard eighth-day commencement, deferring them to 1 January 2026, and their numbering sits well past the incident-reporting chapter documented here (Articles 64 to 71 and 85). Do Articles 104 and 105 touch the incident-reporting duties documented here at all, or are they unrelated?
- Article 69(3) lets the competent CSIRT set the interim-report deadline anywhere from 48 hours to 7 days depending on the request's scope and complexity. Has the competent CSIRT published sector-specific guidance narrowing that range for any particular sector?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 37 of the Cybersecurity Act requires every essential and important entity to notify the competent CSIRT of every incident with a significant effect on the availability, integrity, confidentiality or authenticity of data material to the entity's business or on the continuity of the services it provides (a significant incident), and Article 38 requires it to notify the recipients of its services of a significant incident likely to affect them and, on a serious cyber threat, of protective measures or remedies those recipients can take.
Neither article states the notification clock itself: Article 44 delegates the criteria for a significant incident, the type and content of every notification under Articles 37 to 40, and the deadlines for their submission to the implementing regulation Article 24 authorizes. That regulation, the Cybersecurity Regulation (Narodne novine No. 135/2024), sets the clock in its Articles 64 to 71.
An early warning to the competent CSIRT is due without delay and no later than 24 hours after becoming aware of a significant incident (Article 66). An initial notification is due no later than 72 hours (Article 67), or 24 hours instead for a trust service provider (Article 68). An interim report is due on the CSIRT's request, within a period the CSIRT sets of 48 hours to 7 days (Article 69).
A final report is due no later than 30 days after the initial notification (Article 70), or, where the incident is still ongoing at that point, a progress report in its place, repeated every 30 days once the incident has run past 60 days, followed by a final report within 30 days of the last progress report (Article 71).
The Regulation's Article 85 sets a parallel 72-hour clock, running from the entity's own awareness of the incident, for notifying affected service recipients under the Act's Article 38. Article 37(4) and Article 38(3) of the Act each separately give a newly categorized entity 30 days from the date it receives its Article 19(1) categorization notice before these notification duties bind it, a grace period distinct from the per-incident clock the Regulation sets.
The same Chapter Nine penalty structure documented on this jurisdiction's companion risk-management-and-governance row applies to a reporting failure: an essential entity's fine of EUR 10,000 to EUR 10,000,000 or 0.5 to 2 percent of worldwide turnover, an important entity's fine of EUR 5,000 to EUR 7,000,000 or 0.2 to 1.4 percent, whichever is higher in each case, referred by the competent authority to the competent state attorney for misdemeanor prosecution rather than imposed directly.
When LexLint raises it
operates_social_platform
Read the law
Zakon o kibernetičkoj sigurnosti (Narodne novine 14/2024) and Uredba o kibernetičkoj sigurnosti (Narodne novine 135/2024, adopted by the…
Zakon o kibernetičkoj sigurnosti (Narodne novine 14/2024) and Uredba o kibernetičkoj sigurnosti (Narodne novine 135/2024, adopted by the Government on 21 November 2024), both published on the official gazette narodne-novine.nn.hr