THE CLOCK
The LAW now requires what we already do
Slovenia's ZInfV-1 took the number of obliged organisations from about a hundred to about a thousand, and put the board personally on the hook. These are the dates that matter and what they cost if you miss them.
96 days left
NIS2 / ZInfV-1
Slovenia's Information Security Act, in force since 19 June 2025, took the number of obliged organisations from roughly 100 to roughly 1,000. Risk measures, incident reporting, supply-chain security and training, supervised by URSIV.
Up to €10 M or 2% of turnover
What it means for you
453 days left
Cyber Resilience Act
Anyone placing hardware or software with digital elements on the EU market: secure by design, secure defaults, signed updates, and reporting of actively exploited vulnerabilities. Reporting duties start first; full compliance follows on 11 December 2027.
Up to €15 M or 2.5% of turnover
What it means for you
In force now
DORA
Every EU bank, insurer, broker, payment and crypto firm. ICT risk framework with the board accountable, major incidents classified and reported, a register of every ICT provider, and threat-led penetration testing.
Up to 2% of global turnover
What it means for you
Contract requirement
ISO/IEC 27001
Not a law but a contract requirement: increasingly the price of bidding at all. SIST EN ISO/IEC 27001:2023 is the Slovenian adoption. We take organisations from gap analysis to a certifiable management system.
Lost tenders
What it means for you