Skip to content

NIS2

Directive (EU) 2022/2555 (NIS2)

NIS2 is the EU directive on a high common level of cybersecurity, requiring in-scope entities to manage cyber risk, report incidents and hold management accountable. In Slovenia it is transposed by the Information Security Act (ZInfV-1).

Who it applies to

  • As a rule, medium-sized and larger organizations (per Commission Recommendation 2003/361/EC) in the covered sectors.
  • High-criticality sectors (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space.
  • Other critical sectors (Annex II): postal and courier services, waste management, chemicals, food, manufacturing of critical products, digital providers, research.
  • Some entities are covered regardless of size (e.g. DNS service providers, TLD registries, qualified trust service providers).
  • Essential and important entities face different levels of supervision.

Key obligations

  • Risk analysis and information system security policies.
  • Incident handling and business continuity (backups, disaster recovery, crisis management).
  • Supply chain security and security in acquisition, development and maintenance of systems.
  • Policies to assess the effectiveness of measures, basic cyber hygiene and training.
  • Cryptography and encryption, human resources security, access control and asset management.
  • Multi-factor authentication and secured communications.
  • Management accountability: management bodies must approve and oversee measures, undergo training, and can be held liable for infringements (Article 20).

Penalties

For essential entities, administrative fines of up to at least EUR 10 million or at least 2% of total worldwide annual turnover, whichever is higher; for important entities up to at least EUR 7 million or 1.4% of turnover (Article 34).

Status in Slovenia

The Information Security Act (ZInfV-1) was published in Official Gazette RS No. 40/25 and has been in force since 19 June 2025. The competent authority is the Government Office for Information Security (URSIV). In-scope entities must self-register; entities that meet the criteria later have 30 days to register.

Important notice

This is general information, not legal advice. The content is verified against primary sources (EUR-Lex, Official Gazette RS), but regulations change and their application depends on each organization's circumstances. Consult a legal professional for a binding assessment.

Sources and standards

  1. 01Directive (EU) 2022/2555 (NIS2) on a high common level of cybersecurityEUR-Lex, 2022
  2. 02Slovenian Information Security Act (ZInfV-1), Official Gazette RS No. 40/25 — NIS2 transpositionUradni list RS, 2025
  3. 03Government Office for Information Security of the Republic of Slovenia (URSIV)Republika Slovenija
  4. 04ENISA Threat Landscape 2025ENISA, 2025

Ready to strengthen security across your organization?

Contact us to see how our turnkey solutions can build a safer, more resilient organization.