NIS2 · ZInfV-1
Self-assessment: NIS2 / ZInfV-1 and security maturity
Check whether the new Information Security Act covers you, what is required and by when — then how mature your security posture is. No sign-up; answers stay in your browser.
The new Information Security Act (Official Gazette 40/25) transposes NIS2 and applies from 19 June 2025. Check in a few steps whether you are an essential or important entity, with a clear view of duties, deadlines and official sources.
Answers stay in your browser — nothing is stored or transmitted.
Which sectors do you operate in?
Select everything that applies. Sectors follow Annexes 1 and 2 of ZInfV-1; open a sector to pick the precise activity.
Partner platform
From self-check to a documented risk assessment
Security documentation under Article 21 of ZInfV-1 requires a risk analysis with a defined accepted risk level. Sec Manager walks you through that step in a structured, repeatable way.
Guided, standards-based questionnaires
Risk assessment per ISO 31000, ISO/IEC 27005 and ISO 22301.
Public-source situational awareness
Continuous view of threats and events relevant to your environment.
A repeatable, documented output
Comparable assessments over time — a basis for management and audits.
ZInfV-1 deadlines
What is due, and when
From the EU directive to the final transitional deadline: the obligation timeline for companies, with today marked on the line.
- 16 Jan 2023EU
NIS2 Directive enters into force
Directive 2022/2555/EU replaces NIS1 and greatly widens the set of covered entities across the EU.
Direktiva 2022/2555/EU
- 17 Oct 2024EU
National transposition deadline
The date by which member states had to transpose NIS2. Slovenia transposed it with ZInfV-1 in 2025.
41. člen Direktive 2022/2555/EU
- 23 May 2025Slovenia
Parliament adopts ZInfV-1
The new Information Security Act is published on 4 Jun 2025 in the Official Gazette no. 40/25.
Uradni list RS, št. 40/25
- 19 Jun 2025Slovenia
ZInfV-1 enters into force
The previous ZInfV is repealed. All transitional deadlines for entities run from this date.
69. in 70. člen ZInfV-1
- 19 Oct 2025Slovenia
Self-registration mechanism
URSIV establishes the self-registration mechanism; until then filings run via e-mail.
60. člen (1) ZInfV-1
- 19 Dec 2025EntitiesKey deadline
First self-registration deadline
Existing entities had to register with URSIV. If you have not, do so immediately — omission is an offence.
60. člen (2) ZInfV-1
- 19 Jan 2026Slovenia
First register of entities
URSIV establishes the register of essential and important entities from the filings.
60. člen (4) ZInfV-1
- 19 Jun 2026Entities
Measures for entities under the previous ZInfV
Legacy essential-service providers, state administration and telecom operators must adopt the measures within one year. The same day, URSIV launches the digital incident-reporting platform.
62. člen (2)(3) in 60. člen (6) ZInfV-1
- 19 Dec 2026EntitiesKey deadline
Deadline to adopt all measures
All essential and important entities must have their security documentation (Art. 21) and measures (Art. 22) in place. The 18-month transition ends.
62. člen (1) ZInfV-1
Standing duties
Once the measures are in place the work continues — these duties keep running.
Incidents: 24 h / 72 h / 1 month
Early warning, notification and final report to the competent CSIRT for every significant incident.
ZInfV-1, 30. člen
Conformity assessment every 2 years
Essential entities via audit, important entities via self-assessment and statement.
ZInfV-1, 25. člen
Measure checks at least yearly
Regular effectiveness reviews of the measures and remediation of identified gaps.
ZInfV-1, 22. člen (5)
Management training every 4 years
Responsible persons train on risk management; staff train regularly.
ZInfV-1, 20. člen
Seven questions on actual practice — from policies to incident response. The result shows your gaps whether or not you are in scope.
Question 1 of 7
Does your organization have an adopted umbrella security policy?
A document setting security responsibilities, rules and objectives across the whole organization.
Partner platform
From self-check to a documented risk assessment
The orientation self-check reveals gaps — the next step is a structured, repeatable risk assessment you can put in front of management.
Guided, standards-based questionnaires
Risk assessment per ISO 31000, ISO/IEC 27005 and ISO 22301.
Public-source situational awareness
Continuous view of threats and events relevant to your environment.
A repeatable, documented output
Comparable assessments over time — a basis for management and audits.
