96 days left
NIS2 / ZInfV-1
Slovenia implemented NIS2 as ZInfV-1, in force since 19 June 2025. It took the number of obliged organisations from roughly one hundred to roughly one thousand, and it moved accountability off the IT department and onto management personally.
Are you in scope?
Two questions decide it: what sector you operate in, and how large you are. Size is the easy half — the law reaches medium and large organisations, meaning fifty staff or more, or turnover above ten million euro. Sector is where most organisations get it wrong, because the list is much broader than "critical infrastructure" suggests, and because being a supplier to someone in scope pulls you in through their obligations even when you are not directly named.
Essential entities — the high-criticality sectors
- Energy
- Transport — road, rail, air and water
- Banking and financial market infrastructure
- Health
- Drinking water and waste water
- Digital infrastructure and managed service providers
- Public administration
- Space
Important entities — the other critical sectors
- Postal and courier services
- Waste management
- Chemicals — manufacture and distribution
- Food production and processing
- Manufacturing of medical devices, electronics and machinery
- Digital providers — marketplaces, search, social platforms
- Research organisations
THE DATES
Where this stands today
-
ZInfV-1 in force
-
Deadline for first self-registration with URSIV
-
Risk-management measures expected to be in place
What it actually requires
- Registration with URSIV, the government office that supervises and sanctions
- Risk-management measures, documented and reviewed rather than asserted
- Incident reporting: an early warning within 24 hours, a full notification within 72, a final report within a month
- Supply-chain security — your suppliers become your responsibility
- Business continuity and recovery planning, tested rather than filed
- Training, including for the management that now carries the liability
What it costs to get wrong
Essential entities face up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face up to €7 million or 1.4%. Beyond the corporate fine, ZInfV-1 provides for administrative fines against individual managers, and NIS2 allows a regulator to suspend a senior manager from their duties. This is the part that changes the conversation: the risk is no longer only the company's.
WHAT WE DO ABOUT IT
The services that close this gap
Not the whole catalogue — these are the ones that map onto the obligations above. If something here is already covered internally, say so and we will scope around it.
Security Operations Center
Analysts watching your estate around the clock, with the tooling and the honeypots to see an intrusion while it is still an intrusion and not yet a breach.
Read more CISOaaSChief Information Security Officer
A security executive on subscription: policy, risk register, board reporting and the evidence an auditor asks for — without a six-figure hire.
Read more TPRMaaSThird-party risk management
Your suppliers are your attack surface, and under NIS2 they are also your legal responsibility. We inventory them, rate them and keep watching.
Read more IRIncident response
Containment, eradication and recovery, on site if it needs to be. The 24-hour clock in the law starts the moment you notice, not the moment you call.
Read moreNot sure whether NIS2 / ZInfV-1 applies to you?
Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.