NIS2 Slovenia: zakon o informacijski varnosti (ZInfV-1)
Slovenia transposed NIS2 through the Information Security Act (Zakon o informacijski varnosti, ZInfV-1), in force since 19 June 2025. This page sets out the 30-day self-registration duty and exactly what it asks for, the two CSIRTs, the full 24-hour and 72-hour reporting chain, fines that carry both a minimum percentage and a statutory floor — and the reason your deadline for risk-management measures may already have passed.
Introduction: NIS2 Directive & the Slovenian context
Slovenia previously regulated cybersecurity through the 2018 Information Security Act (ZInfV), which implemented the original NIS Directive and created a national framework for operators of essential services, digital service providers and key state systems.
Directive (EU) 2022/2555 (NIS2) required a comprehensive overhaul. The new Information Security Act (Zakon o informacijski varnosti, ZInfV-1) replaces the old act outright, broadens the number and types of entities in scope, raises the minimum security requirements, tightens the reporting deadlines and rebuilds the sanctions regime.
NIS2 implementation in Slovenia
Slovenia transposed NIS2 through the Information Security Act (Zakon o informacijski varnosti, ZInfV-1), adopted by the Državni zbor on 23 May 2025, published in Uradni list RS 40/2025 of 4 June 2025 (item 1571, page 4310). Article 70 brings it into force on the fifteenth day after publication — 19 June 2025. Every deadline on this page is measured from that date.
ZInfV-1 also implements the Cybersecurity Act (Regulation (EU) 2019/881) and Regulation (EU) 2021/887 establishing the European Cybersecurity Competence Centre, and works alongside the Critical Infrastructure Act.
ZInfV-1 replaces and updates the previous Information Security Act (ZInfV) from 2018. It establishes a modern national cybersecurity system, clarifies roles and responsibilities, and significantly expands the set of obliged entities to include both private and public sector organisations across all NIS2 sectors and some additional national priorities such as research and higher education.
The act follows the NIS2 structure but adds national detail through annexes that list covered sectors, sub-sectors, specific laws and public administration entities, as well as technical requirements and implementation deadlines.
Status
NIS2 is fully transposed in Slovenia. ZInfV-1 has been in force since 19 June 2025 and now serves as the core national cybersecurity law for NIS2-relevant entities.
Legal structure
ZInfV-1 is a horizontal act that defines scope, obligations, authorities, registry rules and sanctions for essential and important entities, supported by implementing acts and annexes that specify sectors, public bodies and detailed requirements.
Transition from old law
Article 61 carries entities over automatically: anyone designated an essential service operator before 16 January 2023 under the old ZInfV, and state administration bodies designated under its Article 9, continue as essential entities with no re-designation — and on the shorter deadline.
Who is in scope in Slovenia
ZInfV-1 mirrors the NIS2 distinction between essential entities and important entities, and uses annexes to list in-scope sectors, services and public bodies. It adopts the NIS2 size-cap rule (medium and large entities) but also includes some size-independent entities where national risks justify it.
Who is in scope?
- Entities operating in NIS2 Annex I sectors of high criticality (energy, transport, banking, financial market infrastructures, health, drinking water, digital infrastructure, public administration, etc.).
- Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, ICT service management, research, etc.).
- Additional Slovenian sectors such as research and higher education institutions, explicitly brought into scope by ZInfV-1.
- Size-independent entities such as DNS and TLD operators, trust-service providers, major cloud providers and certain central ICT system operators for the state.
Core obligations
- Implement technical and organisational measures for information and cybersecurity based on risk, aligned with NIS2 Article 21 and detailed in ZInfV-1 and secondary acts.
- Maintain policies and procedures for asset management, access control, network and system security, vulnerability and patch management, backup and recovery, logging and monitoring.
- Prepare and maintain incident-management plans and business continuity / disaster recovery procedures covering cyber incidents.
- Report significant incidents and certain cyber threats to SI-CERT within strict deadlines (initial notification typically within 24 hours, followed by updates and a final report).
- Manage supply-chain cybersecurity risk, including security, audit and notification clauses in contracts with key suppliers and service providers.
- Ensure that management bodies approve cybersecurity strategies, oversee implementation and regularly receive training and reporting on cyber risk.
Deadlines & transition period
ZInfV-1 introduces a phased approach: essential and important entities must implement the core risk-management measures within a defined period after the law’s entry into force (generally within 18 months for risk-management measures, with further time limits for some detailed requirements and audits).
Self-registration: a rolling 30-day duty
Nobody sends you a letter. Article 8 requires you to register yourself through URSIV's self-registration mechanism within 30 days of the circumstances arising that make you meet the criteria in Articles 6 and 7 — or within 30 days of being served a decision, where URSIV has determined that you are in scope.
The 2025 cohort
URSIV had four months from entry into force to stand the mechanism up (to around 19 October 2025), and entities that already met the criteria had six months to complete their first registration (to around 19 December 2025). Before the mechanism existed, submissions went by email.
If you qualify later
The 30-day clock applies instead, from the day the circumstances arise. Growth across the 50-employee or EUR 10 million threshold is enough to start it.
The reporting platform
URSIV had one year (to around 19 June 2026) to establish the dedicated digital platform for incident notifications. Until it is live, notifications under Articles 29 and 35 go to the competent CSIRT's email address.
What the registration actually asks for
More than most member states, and worth preparing before you start:
- Name, address, contact details, registration number and an electronic address for service.
- The sector and subsector from Annex 1 or Annex 2 in which you provide the listed services — or the category you fall into under Article 6(3) if you are not in the annexes.
- Whether you have at least 50 employees and annual turnover or balance sheet total of at least EUR 10 million.
- Whether you have at least 250 employees, or turnover of at least EUR 50 million, or a balance sheet total of at least EUR 43 million — the essential-entity test.
- An information security contact person and a deputy, with email addresses and telephone numbers.
- Your allocated public IP address blocks and registered autonomous system numbers.
- The EU member states where you provide services falling under the Act.
Incident reporting: 24 hours, 72 hours, one month
Four stages, plus two reports that appear only in particular circumstances. Everything goes to the CSIRT competent for you — SIGOV-CERT for public administration, SI-CERT for everyone else.
NIS2 timeline & key dates (Slovenia)
Sector-specific notes for Slovenia
- Energy: electricity, gas and other energy providers are classified as essential entities with strict resilience, monitoring and incident-reporting obligations.
- Digital infrastructure & telecom: electronic communications networks, internet and cloud infrastructure, data centres and related services are a central focus. Supervision sits with URSIV and the Information Society Inspectorate — not with AKOS, which the Act involves only through cooperation and information exchange. Note that electronic communications operators were on the shorter measures deadline of 19 June 2026.
- Public administration: central government bodies and listed public administration entities are explicitly in scope via dedicated annexes to ZInfV-1.
- Research & higher education: universities and research institutions are specifically mentioned as in-scope entities, reflecting Slovenia’s emphasis on protecting knowledge and innovation infrastructure.
- Critical infrastructure & CER: ZInfV-1 works together with the Critical Infrastructure Act to cover critical entities whose disruption would significantly affect essential services or national security.
Penalties and fines
Slovenian fines under ZInfV-1 are prekrški — misdemeanours — and the structure is unusual in two ways that no published summary captures. The percentage has a floor as well as a ceiling, and there is a statutory minimum in euros.
| Entity | Percentage of total annual turnover | Euro floor | Euro cap |
|---|---|---|---|
| Essential entities (Article 52) | 0.5 % to 2 % of the previous business year's total annual turnover | EUR 10,000 | EUR 10,000,000 |
| Important entities (Article 53) | 0.3 % to 1.4 % | EUR 7,000 | EUR 7,000,000 |
The Act applies whichever amount is higher. Note that it says skupnega letnega prometa — total annual turnover — and not worldwide turnover; the word does not appear in the statute.
The second tier nobody publishes
Alongside the headline provisions, ZInfV-1 sets ordinary misdemeanour ranges for lesser breaches and for other categories of person. For a small organisation these are the figures that actually apply:
| Range | Who |
|---|---|
| EUR 5,000 – 25,000 | Sole trader or self-employed person |
| EUR 3,000 – 20,000 | Sole trader that is an important entity |
| EUR 3,000 – 15,000 | Legal person, for the lesser breaches |
| EUR 1,000 – 10,000 | Sole trader; and the responsible person of a legal entity |
| EUR 1,000 – 7,000 | Responsible person, important-entity breaches |
| EUR 200 – 7,000 | Responsible persons of legal entities, state bodies and municipalities, graded by breach |
Your deadline is one of three, and two have passed
Article 62 sets the deadline for adopting the risk-management measures in Articles 21 and 22. It is the provision most often summarised as “18 months”, and that summary is wrong for two large groups of entities.
| Who you are | Deadline | Status |
|---|---|---|
| Essential entities already designated as essential service operators under the old ZInfV, and state administration bodies designated under its Article 9 | One year from entry into force — 19 June 2026 | Passed. Until that date the old ZInfV security requirements, documentation, supervision and penalty provisions continued to apply to you |
| Essential or important entities that are operators under the Electronic Communications Act | One year — 19 June 2026 | Passed. Until then the security measures in Chapter VII of that Act applied |
| Everyone else — all other essential and important entities | 18 months — 19 December 2026 | Still open |
A separate 18-month clock runs to 19 December 2026 for TLD registries and domain registration service providers to bring their registration databases into line with Article 33 for registrations made before the Act took effect.
Supervision and inspection
Who actually inspects
The Information Society Inspectorate carries out inspection supervision and runs the misdemeanour proceedings that produce a fine. URSIV is the policy and coordination authority; the inspectorate is the enforcement one.
Joint inspections across borders
Where there is a joint agreement, an inspector may carry out joint inspection supervision together with the competent authorities of other EU member states — relevant if you operate in several.
The data protection interface
The inspector notifies the Information Commissioner where a personal data breach is suspected, and must inform AKOS where the matter concerns an operator under the electronic communications law.
How Slovenia differs from the Directive
- A minimum percentage, not just a maximum. 0.5 % to 2 % for essential entities and 0.3 % to 1.4 % for important ones. The Directive sets ceilings only, and only Croatia does the same.
- A statutory euro floor of EUR 10,000 / EUR 7,000, plus a whole second tier of misdemeanour ranges from EUR 200 upwards.
- Priced personal liability for the responsible person, in defined ranges.
- Two CSIRTs, split between public administration and everyone else.
- Three different deadlines for the same obligation, depending on what you were regulated as before.
- Registration asks for network identifiers — public IP blocks and autonomous system numbers — not just corporate details.
- Research and higher education are in scope as a national addition, alongside the Directive's sectors.
- Banka Slovenije is expressly excluded from being an obliged entity.
Slovenian terms you will meet
The Act, the register and all correspondence are in Slovenian. These are the terms worth recognising.
| Slovenian | What it means |
|---|---|
| zakon o informacijski varnosti | The Information Security Act — how Slovenians refer to ZInfV-1 |
| bistveni subjekt | Essential entity |
| pomembni subjekt | Important entity |
| zavezanec | Obliged entity — the general term for anyone in scope |
| samoregistracija | The self-registration mechanism |
| zgodnje sporočilo | The 24-hour early warning |
| priglasitev incidenta | The 72-hour incident notification |
| vmesno poročilo | Interim report, on CSIRT request |
| končno poročilo | The final report, one month after notification |
| poročilo o napredku | Progress report, where the incident is unresolved |
| globa | Fine |
| prekršek | Misdemeanour — the legal category the fines sit in |
| odgovorna oseba | The responsible person, who carries a personal fine range |
| Uradni list | The Official Gazette, where the Act is published |
How to prepare for NIS2 in Slovenia
- Check whether you are in scope: assess your sector, services and size against NIS2 Annex I & II and verify whether you appear in ZInfV-1 annexes as an essential or important entity.
- Establish which CSIRT is yours: SIGOV-CERT if you are a public administration body, SI-CERT otherwise. Supervision sits with URSIV and the Information Society Inspectorate in either case.
- Register, if you have not: the Article 8 duty runs 30 days from the day you meet the criteria, and it asks for your public IP blocks and AS numbers as well as company details.
- Run a NIS2/ZInfV-1 gap assessment: compare your current governance, technical measures, processes and documentation against legal requirements and any guidance published by URSIV and SI-CERT.
- Work out which of the three deadlines is yours: if you were regulated under the old ZInfV, or you are an electronic communications operator, your deadline was 19 June 2026 and has passed. Everyone else has until 19 December 2026.
- Build the reporting chain, not just the first step: a 24-hour early warning, a 72-hour notification, interim reports on request, and a final report one month after the notification — with 24 hours instead of 72 if you are a trust service provider.
- Address supply-chain risk: identify critical suppliers and update contracts to include cybersecurity, audit and incident-notification clauses that are consistent with ZInfV-1.
- Use established frameworks: align your information security management system with standards such as ISO/IEC 27001 or NIST CSF to structure your compliance efforts and evidence.
- Engage leadership early: brief the board and senior management on their roles and potential liabilities, and make cybersecurity a standing topic in risk and strategy discussions.
