Alessandro AleddaInsider Threat and Risk

ITER/HRCroatia

What the record establishes for Croatia: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
Recorded
NIS2
Date not read
Terms moved
Yes
Sources cited
5
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Agencija za zaštitu osobnih podataka reportededpb members
CSIRT or competent authorityNIS2, article 23The competent CSIRT, under article 37 of the Act. NCSC-HR for the public sector, the Nacionalni CERT at CARNET for the private reported

https://pixi.carnet.hr/checked 2026-09-03

The Act does not set one. The competent CSIRT runs the PiXi platform, and access to it is «isključivo ovlaštene osobe putem Nacionalnog identifikacijskog i autentifikacijskog sustava»: authorized persons only, through the national identification system, with the authorization granted beforehand by the entity's legal representative through e-Ovlaštenja. Which CSIRT is competent depends on the entity: NCSC-HR for state bodies, public-law bodies and local government, the Nacionalni CERT for the private sector.

hr zks uredba · cert hr zks incident
Financial supervisorDORA, article 19Hrvatska narodna banka reportedeba competent authorities
Market authorityMAR, article 17Hrvatska agencija za nadzor financijskih usluga (HANFA) reportedesma mar nca

Transposition of NIS2 binding

ActZakon o kibernetičkoj sigurnosti, NN 14/2024
In forceThe Act takes effect on the eighth day after publication, by article 116. The exact date is not printed in the Act.
RecipientThe competent CSIRT, under article 37 of the Act
Moves a termYes. In three ways, and the first one is where to look. The Act sets no deadline at all. Article 37 states the duty to notify the competent CSIRT and the threshold, and stops. Every term is in the Uredba. There the anchors hold: the early warning within «24 sata od trenutka saznanja za značajan incident» and the initial notification within «72 sata» on the same footing, with trust service providers at twenty-four hours. The final report is thirty days, not one month. Article 70 of the Uredba gives «najkasnije u roku od 30 dana od dana dostave početne obavijesti». The interim report has a window the Directive does not set: article 69 lets the CSIRT fix the deadline, but «ne može biti kraći od 48 sati niti duži od sedam dana».
StandingBoth instruments were read: the Act, and the Uredba o kibernetičkoj sigurnosti, NN 135/2024, which is where the cascade actually is. The point worth carrying is structural rather than numerical: an organization that reads the Croatian act and stops has the duty, the recipient and the threshold, and not one hour of the cascade. The thirty days are a real difference from a month, in the months that are longer.
Sourcehr zks uredba

An event in Croatia

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.