ITER/HRCroatia
What the record establishes for Croatia: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | Agencija za zaštitu osobnih podataka reported | — | edpb members |
| CSIRT or competent authorityNIS2, article 23 | The competent CSIRT, under article 37 of the Act. NCSC-HR for the public sector, the Nacionalni CERT at CARNET for the private reported | https://pixi.carnet.hr/checked 2026-09-03 The Act does not set one. The competent CSIRT runs the PiXi platform, and access to it is «isključivo ovlaštene osobe putem Nacionalnog identifikacijskog i autentifikacijskog sustava»: authorized persons only, through the national identification system, with the authorization granted beforehand by the entity's legal representative through e-Ovlaštenja. Which CSIRT is competent depends on the entity: NCSC-HR for state bodies, public-law bodies and local government, the Nacionalni CERT for the private sector. | hr zks uredba · cert hr zks incident |
| Financial supervisorDORA, article 19 | Hrvatska narodna banka reported | — | eba competent authorities |
| Market authorityMAR, article 17 | Hrvatska agencija za nadzor financijskih usluga (HANFA) reported | — | esma mar nca |
Transposition of NIS2 binding
| Act | Zakon o kibernetičkoj sigurnosti, NN 14/2024 |
|---|---|
| In force | The Act takes effect on the eighth day after publication, by article 116. The exact date is not printed in the Act. |
| Recipient | The competent CSIRT, under article 37 of the Act |
| Moves a term | Yes. In three ways, and the first one is where to look. The Act sets no deadline at all. Article 37 states the duty to notify the competent CSIRT and the threshold, and stops. Every term is in the Uredba. There the anchors hold: the early warning within «24 sata od trenutka saznanja za značajan incident» and the initial notification within «72 sata» on the same footing, with trust service providers at twenty-four hours. The final report is thirty days, not one month. Article 70 of the Uredba gives «najkasnije u roku od 30 dana od dana dostave početne obavijesti». The interim report has a window the Directive does not set: article 69 lets the CSIRT fix the deadline, but «ne može biti kraći od 48 sati niti duži od sedam dana». |
| Standing | Both instruments were read: the Act, and the Uredba o kibernetičkoj sigurnosti, NN 135/2024, which is where the cascade actually is. The point worth carrying is structural rather than numerical: an organization that reads the Croatian act and stops has the duty, the recipient and the threshold, and not one hour of the cascade. The thirty days are a real difference from a month, in the months that are longer. |
| Source | hr zks uredba |
An event in Croatia
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
