NIS2 Country Guide

NIS2 Slovenia: zakon o informacijski varnosti (ZInfV-1)

Slovenia transposed NIS2 through the Information Security Act (Zakon o informacijski varnosti, ZInfV-1), in force since 19 June 2025. This page sets out the 30-day self-registration duty and exactly what it asks for, the two CSIRTs, the full 24-hour and 72-hour reporting chain, fines that carry both a minimum percentage and a statutory floor — and the reason your deadline for risk-management measures may already have passed.

In force: 19 June 2025 Authority: URSIV CSIRTs: SI-CERT and SIGOV-CERT Register within 30 days Last updated: 11 August 2026

Introduction: NIS2 Directive & the Slovenian context

Slovenia previously regulated cybersecurity through the 2018 Information Security Act (ZInfV), which implemented the original NIS Directive and created a national framework for operators of essential services, digital service providers and key state systems.

Directive (EU) 2022/2555 (NIS2) required a comprehensive overhaul. The new Information Security Act (Zakon o informacijski varnosti, ZInfV-1) replaces the old act outright, broadens the number and types of entities in scope, raises the minimum security requirements, tightens the reporting deadlines and rebuilds the sanctions regime.

The single most important thing on this page: ZInfV-1 does not give everyone the same deadline for risk-management measures. There are three, and two of them expired on 19 June 2026. Guidance that says “18 months” is describing only one of the three. Which one applies to you.
Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

NIS2 implementation in Slovenia

Slovenia transposed NIS2 through the Information Security Act (Zakon o informacijski varnosti, ZInfV-1), adopted by the Državni zbor on 23 May 2025, published in Uradni list RS 40/2025 of 4 June 2025 (item 1571, page 4310). Article 70 brings it into force on the fifteenth day after publication — 19 June 2025. Every deadline on this page is measured from that date.

ZInfV-1 also implements the Cybersecurity Act (Regulation (EU) 2019/881) and Regulation (EU) 2021/887 establishing the European Cybersecurity Competence Centre, and works alongside the Critical Infrastructure Act.

ZInfV-1 replaces and updates the previous Information Security Act (ZInfV) from 2018. It establishes a modern national cybersecurity system, clarifies roles and responsibilities, and significantly expands the set of obliged entities to include both private and public sector organisations across all NIS2 sectors and some additional national priorities such as research and higher education.

The act follows the NIS2 structure but adds national detail through annexes that list covered sectors, sub-sectors, specific laws and public administration entities, as well as technical requirements and implementation deadlines.

Status

NIS2 is fully transposed in Slovenia. ZInfV-1 has been in force since 19 June 2025 and now serves as the core national cybersecurity law for NIS2-relevant entities.

Legal structure

ZInfV-1 is a horizontal act that defines scope, obligations, authorities, registry rules and sanctions for essential and important entities, supported by implementing acts and annexes that specify sectors, public bodies and detailed requirements.

Transition from old law

Article 61 carries entities over automatically: anyone designated an essential service operator before 16 January 2023 under the old ZInfV, and state administration bodies designated under its Article 9, continue as essential entities with no re-designation — and on the shorter deadline.

Who is in scope in Slovenia

ZInfV-1 mirrors the NIS2 distinction between essential entities and important entities, and uses annexes to list in-scope sectors, services and public bodies. It adopts the NIS2 size-cap rule (medium and large entities) but also includes some size-independent entities where national risks justify it.

Who is in scope?

  • Entities operating in NIS2 Annex I sectors of high criticality (energy, transport, banking, financial market infrastructures, health, drinking water, digital infrastructure, public administration, etc.).
  • Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, ICT service management, research, etc.).
  • Additional Slovenian sectors such as research and higher education institutions, explicitly brought into scope by ZInfV-1.
  • Size-independent entities such as DNS and TLD operators, trust-service providers, major cloud providers and certain central ICT system operators for the state.

Core obligations

  • Implement technical and organisational measures for information and cybersecurity based on risk, aligned with NIS2 Article 21 and detailed in ZInfV-1 and secondary acts.
  • Maintain policies and procedures for asset management, access control, network and system security, vulnerability and patch management, backup and recovery, logging and monitoring.
  • Prepare and maintain incident-management plans and business continuity / disaster recovery procedures covering cyber incidents.
  • Report significant incidents and certain cyber threats to SI-CERT within strict deadlines (initial notification typically within 24 hours, followed by updates and a final report).
  • Manage supply-chain cybersecurity risk, including security, audit and notification clauses in contracts with key suppliers and service providers.
  • Ensure that management bodies approve cybersecurity strategies, oversee implementation and regularly receive training and reporting on cyber risk.

Deadlines & transition period

ZInfV-1 introduces a phased approach: essential and important entities must implement the core risk-management measures within a defined period after the law’s entry into force (generally within 18 months for risk-management measures, with further time limits for some detailed requirements and audits).

Key takeaway: Even though ZInfV-1 has only recently entered into force, the compliance clock is already ticking. Entities should not wait for inspections or additional guidance before starting their NIS2/ZInfV-1 programmes.

Self-registration: a rolling 30-day duty

Nobody sends you a letter. Article 8 requires you to register yourself through URSIV's self-registration mechanism within 30 days of the circumstances arising that make you meet the criteria in Articles 6 and 7 — or within 30 days of being served a decision, where URSIV has determined that you are in scope.

The 2025 cohort

URSIV had four months from entry into force to stand the mechanism up (to around 19 October 2025), and entities that already met the criteria had six months to complete their first registration (to around 19 December 2025). Before the mechanism existed, submissions went by email.

If you qualify later

The 30-day clock applies instead, from the day the circumstances arise. Growth across the 50-employee or EUR 10 million threshold is enough to start it.

The reporting platform

URSIV had one year (to around 19 June 2026) to establish the dedicated digital platform for incident notifications. Until it is live, notifications under Articles 29 and 35 go to the competent CSIRT's email address.

What the registration actually asks for

More than most member states, and worth preparing before you start:

  • Name, address, contact details, registration number and an electronic address for service.
  • The sector and subsector from Annex 1 or Annex 2 in which you provide the listed services — or the category you fall into under Article 6(3) if you are not in the annexes.
  • Whether you have at least 50 employees and annual turnover or balance sheet total of at least EUR 10 million.
  • Whether you have at least 250 employees, or turnover of at least EUR 50 million, or a balance sheet total of at least EUR 43 million — the essential-entity test.
  • An information security contact person and a deputy, with email addresses and telephone numbers.
  • Your allocated public IP address blocks and registered autonomous system numbers.
  • The EU member states where you provide services falling under the Act.
The IP and AS number requirement is unusual. Most member states ask for corporate and contact details. Slovenia asks for network identifiers, which means the registration has to be prepared with someone who runs the infrastructure, not only with legal or compliance.

Authorities and the two CSIRTs

URSIV is the competent national authority and single point of contact. Two things about the rest of the picture are widely misreported: Slovenia has two CSIRTs, not one, and AKOS is not a NIS2 supervisory authority — the Act gives it a cooperation and information-exchange role only.

Role Authority Notes
NIS2 authority & Single Point of Contact Government Information Security Office (URSIV) Acts as the main NIS2 authority and coordinator, prepares legislation and guidance, oversees the national cybersecurity system, participates in EU cooperation networks and coordinates response to large-scale cyber crises.
CSIRT — most organisations SI-CERT, an internal unit of ARNES (Akademska in raziskovalna mreža Slovenije) Article 59. Handles incidents notified by all obliged entities other than public administration, acts as national coordinator, and also takes voluntary reports from organisations not in scope.
CSIRT — public administration SIGOV-CERT, an internal unit of URSIV Article 59. Handles incidents of public administration bodies at state and local level, and trust services operated by state administration bodies. Reports from those bodies do not go to SI-CERT.
Inspection and misdemeanour proceedings Inšpekcija za informacijsko družbo (Information Society Inspectorate) Carries out inspection supervision and conducts the misdemeanour proceedings that lead to a fine. This, not URSIV, is the body that turns up.
Cooperation and information exchange only AKOS (Agencija za komunikacijska omrežja in storitve RS), Informacijski pooblaščenec, Banka Slovenije, Javna agencija za civilno letalstvo, Uprava RS za jedrsko varnost The Act requires cooperation and regular exchange of incident and threat information with these bodies, and requires the inspector to inform AKOS where a matter concerns operators under the electronic communications law. None of them supervises you under ZInfV-1.
Financial-sector lists Banka Slovenije, Agencija za trg vrednostnih papirjev, Agencija za zavarovalni nadzor Send URSIV named lists of ICT-service-management entities in the banking and financial market infrastructure sectors, and of DORA financial entities, within 30 days of identifying them. Banka Slovenije is expressly not an obliged entity under the Act.

Incident reporting: 24 hours, 72 hours, one month

Four stages, plus two reports that appear only in particular circumstances. Everything goes to the CSIRT competent for you — SIGOV-CERT for public administration, SI-CERT for everyone else.

24 hours — early warning (zgodnje sporočilo), stating where relevant whether the incident is suspected to have been caused by an unlawful or malicious act and whether it could have cross-border impact.
72 hours — incident notification (priglasitev incidenta), updating the early warning and adding an initial assessment including severity, impact and, where available, indicators of compromise. Trust service providers have 24 hours, not 72.
On request — interim report (vmesno poročilo) with relevant status updates, whenever the CSIRT asks for one.
One month — final report (končno poročilo), measured from submission of the 72-hour notification. It must contain a detailed description with severity and impact, the threat type or root cause, the mitigating measures applied and still being applied, and any cross-border impact.
If the incident is still running — progress report (poročilo o napredku) instead, with the final report due one month after the incident is resolved.
The CSIRT owes you a response within 24 hours. On receiving the early warning it must reply to you — without delay and where possible within 24 hours — with initial feedback on the incident and, if you ask, guidance or operational advice on mitigation measures, plus further technical support on request. It also informs URSIV. Few organisations know they can hold it to that.

NIS2 timeline & key dates (Slovenia)

2018 — Original Information Security Act (ZInfV) adopted, implementing the first NIS Directive in Slovenia.
14 December 2022 — NIS2 Directive adopted at EU level, setting an October 2024 deadline for national transposition.
10 April 2025 — Government finalises the draft of the new Information Security Act (ZInfV-1) and submits it to Parliament under an urgent procedure.
23 May 2025 — the Državni zbor adopts ZInfV-1.
4 June 2025 — ZInfV-1 is published in the Official Gazette of the Republic of Slovenia.
19 June 2025 — ZInfV-1 enters into force, formally transposing NIS2 into Slovenian law.
19 December 2025 — first self-registration deadline for entities already in scope; Government implementing regulations due.
19 June 2026 — risk-management measures due for entities carried over from the old ZInfV and for electronic communications operators. This deadline has passed.
19 June 2026 — URSIV's dedicated digital reporting platform due.
19 December 2026 — risk-management measures due for everyone else, and deadline for TLD registries to align their domain registration databases.

Sector-specific notes for Slovenia

  • Energy: electricity, gas and other energy providers are classified as essential entities with strict resilience, monitoring and incident-reporting obligations.
  • Digital infrastructure & telecom: electronic communications networks, internet and cloud infrastructure, data centres and related services are a central focus. Supervision sits with URSIV and the Information Society Inspectorate — not with AKOS, which the Act involves only through cooperation and information exchange. Note that electronic communications operators were on the shorter measures deadline of 19 June 2026.
  • Public administration: central government bodies and listed public administration entities are explicitly in scope via dedicated annexes to ZInfV-1.
  • Research & higher education: universities and research institutions are specifically mentioned as in-scope entities, reflecting Slovenia’s emphasis on protecting knowledge and innovation infrastructure.
  • Critical infrastructure & CER: ZInfV-1 works together with the Critical Infrastructure Act to cover critical entities whose disruption would significantly affect essential services or national security.

Penalties and fines

Slovenian fines under ZInfV-1 are prekrški — misdemeanours — and the structure is unusual in two ways that no published summary captures. The percentage has a floor as well as a ceiling, and there is a statutory minimum in euros.

EntityPercentage of total annual turnoverEuro floorEuro cap
Essential entities (Article 52) 0.5 % to 2 % of the previous business year's total annual turnover EUR 10,000 EUR 10,000,000
Important entities (Article 53) 0.3 % to 1.4 % EUR 7,000 EUR 7,000,000

The Act applies whichever amount is higher. Note that it says skupnega letnega prometa — total annual turnover — and not worldwide turnover; the word does not appear in the statute.

The second tier nobody publishes

Alongside the headline provisions, ZInfV-1 sets ordinary misdemeanour ranges for lesser breaches and for other categories of person. For a small organisation these are the figures that actually apply:

RangeWho
EUR 5,000 – 25,000Sole trader or self-employed person
EUR 3,000 – 20,000Sole trader that is an important entity
EUR 3,000 – 15,000Legal person, for the lesser breaches
EUR 1,000 – 10,000Sole trader; and the responsible person of a legal entity
EUR 1,000 – 7,000Responsible person, important-entity breaches
EUR 200 – 7,000Responsible persons of legal entities, state bodies and municipalities, graded by breach
Personal liability is priced. The odgovorna oseba — the responsible person of a legal entity, a sole trader, a state body or a municipality — carries their own fine range alongside the organisation's. Slovenia states the numbers where most member states say only that management is accountable.
What stops the fine. Where the Information Commissioner has already imposed a fine under data protection law for the same personal data breach, the inspector is constrained from punishing the same conduct twice. Slovenia joins Spain, France, Czechia, Croatia and Slovakia in having an express brake of this kind.

Your deadline is one of three, and two have passed

Article 62 sets the deadline for adopting the risk-management measures in Articles 21 and 22. It is the provision most often summarised as “18 months”, and that summary is wrong for two large groups of entities.

Who you areDeadlineStatus
Essential entities already designated as essential service operators under the old ZInfV, and state administration bodies designated under its Article 9 One year from entry into force — 19 June 2026 Passed. Until that date the old ZInfV security requirements, documentation, supervision and penalty provisions continued to apply to you
Essential or important entities that are operators under the Electronic Communications Act One year19 June 2026 Passed. Until then the security measures in Chapter VII of that Act applied
Everyone else — all other essential and important entities 18 months19 December 2026 Still open
Why this catches people. The organisations on the shorter deadline are precisely the ones that were already regulated and therefore assumed they were furthest ahead. Article 61 carried them into ZInfV-1 automatically, without a fresh designation, so there was no letter marking the change.

A separate 18-month clock runs to 19 December 2026 for TLD registries and domain registration service providers to bring their registration databases into line with Article 33 for registrations made before the Act took effect.

Supervision and inspection

Who actually inspects

The Information Society Inspectorate carries out inspection supervision and runs the misdemeanour proceedings that produce a fine. URSIV is the policy and coordination authority; the inspectorate is the enforcement one.

Joint inspections across borders

Where there is a joint agreement, an inspector may carry out joint inspection supervision together with the competent authorities of other EU member states — relevant if you operate in several.

The data protection interface

The inspector notifies the Information Commissioner where a personal data breach is suspected, and must inform AKOS where the matter concerns an operator under the electronic communications law.

How Slovenia differs from the Directive

  • A minimum percentage, not just a maximum. 0.5 % to 2 % for essential entities and 0.3 % to 1.4 % for important ones. The Directive sets ceilings only, and only Croatia does the same.
  • A statutory euro floor of EUR 10,000 / EUR 7,000, plus a whole second tier of misdemeanour ranges from EUR 200 upwards.
  • Priced personal liability for the responsible person, in defined ranges.
  • Two CSIRTs, split between public administration and everyone else.
  • Three different deadlines for the same obligation, depending on what you were regulated as before.
  • Registration asks for network identifiers — public IP blocks and autonomous system numbers — not just corporate details.
  • Research and higher education are in scope as a national addition, alongside the Directive's sectors.
  • Banka Slovenije is expressly excluded from being an obliged entity.

Slovenian terms you will meet

The Act, the register and all correspondence are in Slovenian. These are the terms worth recognising.

SlovenianWhat it means
zakon o informacijski varnostiThe Information Security Act — how Slovenians refer to ZInfV-1
bistveni subjektEssential entity
pomembni subjektImportant entity
zavezanecObliged entity — the general term for anyone in scope
samoregistracijaThe self-registration mechanism
zgodnje sporočiloThe 24-hour early warning
priglasitev incidentaThe 72-hour incident notification
vmesno poročiloInterim report, on CSIRT request
končno poročiloThe final report, one month after notification
poročilo o napredkuProgress report, where the incident is unresolved
globaFine
prekršekMisdemeanour — the legal category the fines sit in
odgovorna osebaThe responsible person, who carries a personal fine range
Uradni listThe Official Gazette, where the Act is published

How to prepare for NIS2 in Slovenia

  1. Check whether you are in scope: assess your sector, services and size against NIS2 Annex I & II and verify whether you appear in ZInfV-1 annexes as an essential or important entity.
  2. Establish which CSIRT is yours: SIGOV-CERT if you are a public administration body, SI-CERT otherwise. Supervision sits with URSIV and the Information Society Inspectorate in either case.
  3. Register, if you have not: the Article 8 duty runs 30 days from the day you meet the criteria, and it asks for your public IP blocks and AS numbers as well as company details.
  4. Run a NIS2/ZInfV-1 gap assessment: compare your current governance, technical measures, processes and documentation against legal requirements and any guidance published by URSIV and SI-CERT.
  5. Work out which of the three deadlines is yours: if you were regulated under the old ZInfV, or you are an electronic communications operator, your deadline was 19 June 2026 and has passed. Everyone else has until 19 December 2026.
  6. Build the reporting chain, not just the first step: a 24-hour early warning, a 72-hour notification, interim reports on request, and a final report one month after the notification — with 24 hours instead of 72 if you are a trust service provider.
  7. Address supply-chain risk: identify critical suppliers and update contracts to include cybersecurity, audit and incident-notification clauses that are consistent with ZInfV-1.
  8. Use established frameworks: align your information security management system with standards such as ISO/IEC 27001 or NIST CSF to structure your compliance efforts and evidence.
  9. Engage leadership early: brief the board and senior management on their roles and potential liabilities, and make cybersecurity a standing topic in risk and strategy discussions.

Official links & resources

ZInfV-1, full text — Uradni list RS 40/2025 — the authoritative published text, item 1571
SI-CERT — the CSIRT for all obliged entities outside public administration

FAQ: NIS2 in Slovenia

Has Slovenia fully transposed NIS2?
Yes. Slovenia has transposed NIS2 through the Information Security Act (ZInfV-1), which entered into force on 19 June 2025 and now serves as the main national cybersecurity law for NIS2-relevant entities.
Which law should we look at for NIS2 compliance?
The primary law is the Information Security Act (ZInfV-1), together with its annexes and any implementing regulations adopted by the Government or URSIV. Older references to the 2018 act (ZInfV) have been superseded by ZInfV-1.
Who is the main NIS2 authority, and is AKOS one of them?
URSIV is the competent national authority and single point of contact, and the Information Society Inspectorate carries out inspections and misdemeanour proceedings. AKOS is not a supervisory authority under ZInfV-1. The Act names it only as a body to cooperate and exchange information with, and one the inspector must inform where a matter concerns an operator under the electronic communications law. Guidance describing AKOS as the sectoral NIS2 regulator with registry oversight is not supported by the Act.
Which CSIRT do we report incidents to?
SIGOV-CERT, an internal unit of URSIV, if you are a public administration body at state or local level, or you operate trust services as a state administration body. SI-CERT, an internal unit of ARNES, for every other obliged entity. SI-CERT also acts as national coordinator and accepts voluntary reports from organisations that are not in scope.
What is our deadline for risk-management measures?
One of three. If you were designated an essential service operator under the old ZInfV, or you are a state administration body designated under its Article 9, or you are an operator under the Electronic Communications Act, your deadline was 19 June 2026 and it has passed. Every other essential or important entity has until 19 December 2026. The commonly quoted “18 months” describes only the third group.
How high can fines be, and is there a minimum?
Yes, there is a minimum, which is unusual. For essential entities the fine is 0.5 % to 2 % of total annual turnover, not less than EUR 10,000 and not more than EUR 10,000,000, whichever is higher. For important entities it is 0.3 % to 1.4 %, not less than EUR 7,000 and not more than EUR 7,000,000. The Act refers to total annual turnover, not worldwide turnover. Separate misdemeanour ranges from EUR 200 upwards apply to lesser breaches and to responsible persons individually.
Do we have to register, and by when?
Yes. Article 8 requires self-registration through URSIV's mechanism within 30 days of meeting the criteria, or of being served a decision that you are in scope. Entities already in scope when the Act started had until around 19 December 2025. The registration asks for your public IP address blocks and autonomous system numbers as well as company and contact details.
Is ISO 27001 certification mandatory?
ISO/IEC 27001 is not mandated by name, but ZInfV-1 requires robust, risk-based security measures. Aligning with ISO 27001 or a similar framework is a practical way to structure, implement and demonstrate compliance with Slovenian NIS2 requirements.
Information provided for general guidance; always consult the published text of the Zakon o informacijski varnosti (ZInfV-1) in Uradni list RS 40/2025, the publications of URSIV and SI-CERT, and legal counsel for definitive NIS2 compliance requirements.