Croatia — Cyber Threat Profile
Entering 2026, Croatia has moved into the active enforcement phase of its Cybersecurity Act, which transposed the EU's NIS2 Directive. Following the 2025 categorization of "essential" and "important" entities, organizations are now required to conduct biennial self-assessments and maintain strict risk-management protocols. The national focus is on protecting the maritime and energy sectors, with the National Security and Information Systems Strategy prioritizing proactive defense. Croatia is also intensifying its participation in EU-wide threat intelligence sharing, leveraging its Single Point of Contact at the UVNS to mitigate cross-border hybrid threats. Compliance remains a boardroom priority, with non-compliance facing significant administrative sanctions.- National CERT/CSIRT: CERT.hr
- Data protection authority: Croatian Personal Data Protection Agency (source: CNIL)
- Secure Internet servers per 1M people (2024): 29,458.6 (source: World Bank)
- Internet users (2024): 83.6% of population (source: World Bank)
Read the full analysis on IntelFusions