CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

COMPLIANCE

Which of these catches you?

Eight regimes, seven of them law. Most organisations are caught by two or three and believe they are caught by none — usually because the obligation arrived as sector regulation, as product law or as data protection, rather than as anything labelled cyber security.

Regime It catches you if Next date Exposure
NIS2 / ZInfV-1 You have 50+ staff or €10 M+ turnover and operate in energy, transport, banking, health, water, digital infrastructure, public administration, waste, chemicals, food, manufacturing, postal or research — or you supply someone who does. 96 days left Up to €10 M or 2% of turnover
AI Act You build, sell, or simply use an AI system — biometrics, video analytics, recruitment screening, risk scoring, or a safety component of critical infrastructure. Buying one makes you a deployer, which carries duties of its own. 444 days left Up to €35 M or 7% of turnover
Cyber Resilience Act You place any product with digital elements on the EU market: hardware, software, firmware, a machine with a controller, an appliance with an app — whether you made it or badged it. 453 days left Up to €15 M or 2.5% of turnover
RED / EN 18031 You place a radio product that can reach the internet on the EU market: a camera, a sensor, a reader, a drone, a wearable, a meter — anything with Wi-Fi, Bluetooth, LTE or LoRa in it. In force now Product refused or withdrawn from the market
DORA You are a bank, insurer, broker, investment firm, payment or e-money institution, crypto service or fund manager — of any size — or you supply ICT to one. In force now Up to 2% of global turnover
GDPR / ZVOP-2 You hold personal data about anybody in the EU. There is no size threshold and no sector list — this one catches everyone, and it is the regime with a decade of enforcement behind it. In force now Up to €20 M or 4% of turnover
ISO/IEC 27001 A customer, a tender or an insurer has asked for it. There is no legal trigger — only a commercial one, and it arrives without warning. Contract requirement Lost tenders
CER You are already an essential entity under ZInfV-1 and the service you run has to keep running through sabotage, drones, flooding or an insider — not only through a cyber attack. Draft in parliament The same entities as ZInfV-1

Being a supplier counts. The commonest mistake is assuming that not being named means not being affected. Supply-chain security is an explicit obligation under both ZInfV-1 and DORA, which means your customer is now required to assess you — and to be able to show a regulator that they did.

IN DETAIL

What each one requires

96 days left

NIS2 / ZInfV-1

Slovenia's Information Security Act, in force since 19 June 2025, took the number of obliged organisations from roughly 100 to roughly 1,000. Risk measures, incident reporting, supply-chain security and training, supervised by URSIV.

Up to €10 M or 2% of turnover

Read the detail
444 days left

AI Act

Anyone placing an AI system on the EU market or putting one into service. Prohibited practices have applied since February 2025 and transparency duties since August 2026; the high-risk obligations — biometric identification, safety components of critical infrastructure, law-enforcement and border use — were moved to 2 December 2027 and 2 August 2028 by the Digital Omnibus.

Up to €35 M or 7% of turnover

Read the detail
453 days left

Cyber Resilience Act

Anyone placing hardware or software with digital elements on the EU market: secure by design, secure defaults, signed updates, and reporting of actively exploited vulnerabilities. Reporting duties start first; full compliance follows on 11 December 2027.

Up to €15 M or 2.5% of turnover

Read the detail
In force now

RED / EN 18031

Since 1 August 2025 every internet-connectable radio product placed on the EU market must meet the cybersecurity essential requirements of the Radio Equipment Directive's delegated act. EN 18031 is the harmonised standard, in three parts: network protection, personal data, and protection from fraud. It already applies to the devices the CRA covers in full from December 2027.

Product refused or withdrawn from the market

Read the detail
In force now

DORA

Every EU bank, insurer, broker, payment and crypto firm. ICT risk framework with the board accountable, major incidents classified and reported, a register of every ICT provider, and threat-led penetration testing.

Up to 2% of global turnover

Read the detail
In force now

GDPR / ZVOP-2

The oldest of these and still the most enforced. ZVOP-2 has been the Slovenian implementing act since January 2023, supervised by the Informacijski pooblaščenec. A breach exposing personal data is reportable within 72 hours whether or not ZInfV-1 also catches you — one incident, two clocks, two regulators.

Up to €20 M or 4% of turnover

Read the detail
Contract requirement

ISO/IEC 27001

Not a law but a contract requirement: increasingly the price of bidding at all. SIST EN ISO/IEC 27001:2023 is the Slovenian adoption. We take organisations from gap analysis to a certifiable management system.

Lost tenders

Read the detail
Draft in parliament

CER

The physical twin of NIS2: the same essential sectors, but resilience against sabotage, drones, natural hazards and insider threat rather than cyber alone. Slovenia had to transpose it by 17 October 2024 and has not yet; the draft is in the legislative process, so this is a deadline to plan for rather than one to report against.

The same entities as ZInfV-1

Read the detail

THE REGION

Your subsidiary in Zagreb or Belgrade has one too

Slovenian organisations operate across the region, and the countries outside the EU have copied NIS2 into national law rather than waiting for accession. A group with entities in six countries now has six supervisors asking the same questions on six different timetables — and supply-chain obligations mean the parent is answerable for all of it.

Country The act Where it stands
Slovenia
EU member
ZInfV-1 (Information Security Act) In force 19 June 2025. Roughly 1,000 obliged entities. Risk-management measures due 19 December 2026; supervised by URSIV. CER is not yet transposed.
Croatia
EU member
Zakon o kibernetičkoj sigurnosti In force February 2024 — one of the earliest NIS2 transpositions in the EU. Obligations and supervision are settled, so a Croatian subsidiary is already being asked for evidence.
Serbia
Outside the EU
Law on Information Security (2025) Adopted 22 October 2025, in force 31 October 2025. Not an EU state, but written to NIS2's mechanisms. Operators have eighteen months to comply, and a new Office for Information Security begins work on 1 January 2027.
North Macedonia
Outside the EU
Security of Network and Information Systems Act Applies from 1 January 2026 and harmonises with Directive (EU) 2022/2555. The essential/important split, annual risk assessment and proportionate measures are all carried over.
Montenegro
Outside the EU
Cybersecurity Act (2024) Adopted 20 November 2024. Distinguishes essential from important entities as NIS2 does, requires risk-management measures and incident reporting, and creates a Cyber Security Agency that supervises against ISO/IEC 27001.
Albania
Outside the EU
Law 25/2024 on Cybersecurity NIS2-aligned since 2024, with a government Security Operations Centre and, since December 2024, the Regional Cyber Capacity Centre for the Western Balkans.

Bosnia and Herzegovina and Kosovo are the gap. Neither has a NIS2-equivalent act in force at the time of writing. If your operation depends on an entity there, the obligation still reaches you — through your own supply-chain duties rather than through theirs.

ON THE HORIZON

Not yet, but soon enough to plan for

These do not have a page of their own because they are not yet biting. They are here because the work they will ask for is work that would already be worth doing.

20 January 2027

Machinery Regulation (EU) 2023/1230

Replaces the Machinery Directive and applies directly, with no national transposition. It puts cybersecurity into safety: a control system that can be corrupted remotely is now a machinery safety defect, not only an IT problem. Relevant to every manufacturer with a connected line.

Proposed 20 January 2026

Revised Cybersecurity Act

The Commission's recast would extend ENISA's mandate and add a mandatory ICT supply-chain framework covering high-risk vendors and high-risk countries, with fines proposed at up to 7% of worldwide turnover. Still a proposal — but supply-chain governance is the direction of travel across every regime on this page.

In force

Cyber Solidarity Act

Creates an EU Cybersecurity Reserve of incident-response providers that a Member State can call on during a significant or large-scale incident, alongside a cross-border detection infrastructure. It changes what help exists in a crisis rather than what you must do beforehand.

Wallets from Member States

eIDAS 2 and the EU Digital Identity Wallet

Every Member State must offer citizens a digital identity wallet, and large platforms must accept it. For anyone operating an authentication flow it changes what "verify a customer" will mean, and it brings a new set of assurance requirements with it.

We will tell you which ones apply, free

Sector, headcount, turnover and what you sell. That is enough to answer the scope question properly, and about half the organisations that ask turn out not to be in scope at all. We would rather tell you that than sell you a programme you do not need.

Ask us to check See the services