Back to Blog

NIS2 in Slovenia: What Organizations Need to Know

January 07, 2025 3 min read
NIS2 in Slovenia: What Organizations Need to Know
Last updated:

Slovenia transposed NIS2 through the Information Security Act (ZInfV-1), effective from 19 June 2025. Organisations should establish whether they are in scope, then assign owners, measures and evidence to their obligations. A penetration test can contribute to security validation; it does not replace the complete risk-management programme.

Who Is Affected

Directive (EU) 2022/2555 (NIS2) distinguishes essential and important entities. In Slovenia, use the criteria and annexes of ZInfV-1. A sector label or the shorthand “50 employees or EUR 10 million turnover” is not a sufficient classification test.

  • Activities and services: Check the specific sector, subsector and service in the annexes, rather than only the registered business activity.
  • Size and special categories: Apply the combination of employees, turnover or balance-sheet total and provisions covering certain entities regardless of size. For linked companies, do not assume that one legal entity's standalone figures settle the assessment.
  • Essential or important: Classification also depends on size and special categories; a sector does not automatically give all its organisations the same status.
  • Suppliers: An entity's contractual security requirements can affect suppliers outside direct statutory scope. That does not automatically give them the same legal status.
  • Financial services: Consider DORA and the exclusions in Article 3 of ZInfV-1. Banks should not be used as a generic example of simply adding all obligations of both regimes.

Key Requirements

Measures should reflect risk and the services provided. Connect risk assessment, management responsibility, incident handling, continuity, supply-chain security and vulnerability handling. Assess whether measures work and retain implementation evidence. See ZInfV-1 implementation and evidence for practical documentation.

Significant Incident Reporting

Under Article 30 of ZInfV-1, entities report significant incidents to their competent CSIRT. The maximum deadlines from detection are 24 hours for an early warning and 72 hours for incident notification; action is required without delay. Trust service providers have a special 24-hour notification deadline.

The final report is normally due no later than one month after the notification. If the incident continues, submit a progress report and provide the final report within one month of resolution. An intermediate report may also be required on the CSIRT's request. These duties concern incidents meeting the statutory significance criteria, not every security-tool alert.

URSIV guidance routes state and local public-administration entities and specified trust service providers to SIGOV-CERT; SI-CERT handles other entities in scope. See incident response for executives for management preparation and decisions.

Supervision, Accountability and Fines

NIS2 Article 34 requires maximum fines for specified infringements of at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher. This is the directive's framework, not an automatic fine for every organisation. Articles 52–56 of ZInfV-1 define Slovenian offences, ranges and fines for responsible persons. Management accountability must be assessed against the particular duty and infringement, rather than described as automatic personal financial liability for every incident.

Slovenian Implementation and Deadlines

URSIV's official publication notice confirms NIS2 transposition through the new act. URSIV is the Government Information Security Office. Its guidance states that entities meeting the criteria when the act took effect had to self-register by 19 December 2025. Check Article 8 and transitional provisions for later applicability and changes; a transition period for one measure does not postpone all obligations.

Where an incident involves personal data, separately assess GDPR and ZVOP-2 obligations. Reporting to a CSIRT does not replace any required notification to the Information Commissioner.

Practical Preparation

  1. Document applicability and classification, and check registration.
  2. Compare applicable obligations with existing procedures and technical controls.
  3. Assign owners, resources and deadlines for missing measures.
  4. Rehearse significant-incident identification, decisions and initial reporting.
  5. Validate implementation and remediation; retain evidence showing what was actually assessed.
Vid Grosek

Vid Grosek

Ethical Hacker & Penetration Tester

I help Slovenian companies discover security vulnerabilities before attackers do. With 18+ years of experience in cybersecurity.

All Posts

Comments

No comments yet. Be the first!

Leave a Comment

Enjoyed this article?

Subscribe to the newsletter for monthly security insights.

Subscribe