96 days left
NIS2 / ZInfV-1
Slovenia's Information Security Act, in force since 19 June 2025, took the number of obliged organisations from roughly 100 to roughly 1,000. Risk measures, incident reporting, supply-chain security and training, supervised by URSIV.
Up to €10 M or 2% of turnover
Read the detail
444 days left
AI Act
Anyone placing an AI system on the EU market or putting one into service. Prohibited practices have applied since February 2025 and transparency duties since August 2026; the high-risk obligations — biometric identification, safety components of critical infrastructure, law-enforcement and border use — were moved to 2 December 2027 and 2 August 2028 by the Digital Omnibus.
Up to €35 M or 7% of turnover
Read the detail
453 days left
Cyber Resilience Act
Anyone placing hardware or software with digital elements on the EU market: secure by design, secure defaults, signed updates, and reporting of actively exploited vulnerabilities. Reporting duties start first; full compliance follows on 11 December 2027.
Up to €15 M or 2.5% of turnover
Read the detail
In force now
RED / EN 18031
Since 1 August 2025 every internet-connectable radio product placed on the EU market must meet the cybersecurity essential requirements of the Radio Equipment Directive's delegated act. EN 18031 is the harmonised standard, in three parts: network protection, personal data, and protection from fraud. It already applies to the devices the CRA covers in full from December 2027.
Product refused or withdrawn from the market
Read the detail
In force now
DORA
Every EU bank, insurer, broker, payment and crypto firm. ICT risk framework with the board accountable, major incidents classified and reported, a register of every ICT provider, and threat-led penetration testing.
Up to 2% of global turnover
Read the detail
In force now
GDPR / ZVOP-2
The oldest of these and still the most enforced. ZVOP-2 has been the Slovenian implementing act since January 2023, supervised by the Informacijski pooblaščenec. A breach exposing personal data is reportable within 72 hours whether or not ZInfV-1 also catches you — one incident, two clocks, two regulators.
Up to €20 M or 4% of turnover
Read the detail
Contract requirement
ISO/IEC 27001
Not a law but a contract requirement: increasingly the price of bidding at all. SIST EN ISO/IEC 27001:2023 is the Slovenian adoption. We take organisations from gap analysis to a certifiable management system.
Lost tenders
Read the detail
Draft in parliament
CER
The physical twin of NIS2: the same essential sectors, but resilience against sabotage, drones, natural hazards and insider threat rather than cyber alone. Slovenia had to transpose it by 17 October 2024 and has not yet; the draft is in the legislative process, so this is a deadline to plan for rather than one to report against.
The same entities as ZInfV-1
Read the detail