Jurica Čular graduated at Faculty of electronics and computer science, Zagreb, Croatia as Master of Computer Science. Got an MBA in finance and marketing at Kelley School of Business, Indiana University. Holds several information security certificates CISA, CISSP, ISO 27001 LA.Worked as an information security consultant for financial institutions and for Deloitte. Currently working as an expert advisor in Information Systems Security Bureau.The NIS Directive is the first piece of EU-wide legislation on cybersecurity. It provides legal measures to boost the overall level of cybersecurity in the EU. The main goal is to ensure harmonization in level of cyber security between member states. Process seems reasonable and most member states agreed on usefulness of such legislation. The fact that NIS is a directive and not a regulation implies that member states should create a legislation in line with NIS. This is where the fun starts. EU member states are very different one from another and creating a harmonization is pretty hard task. How some old and well organized member states are dealing with this task is significantly different than the situation in a rather new member states. This talk will bring insight in a process of transposition of NIS Directive into Croatian legislation. What approach did we take, who were the key players in this process? What are the biases that exist with each key player and what roles were designated to CSIRTs? How did we cope with issues in a society and economy with very low cyber security awareness? These are the questions I will bring answers during the talk. For EU CERTs this would be interesting to hear and compare experiences. For non-EU CERTs this is a good way to hear about good and bad aspects of NIS Directive.